# Security Audit Report — agents-md-generator

- **Report ID:** `6c40c47e-f19a-4750-946b-525711418c1a`
- **Generated:** 2026-08-02T12:27:11.804627+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Unsafe (composite)  
**Security score:** 34.25

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | unavailable |
| cisco-skill-scanner | Caution |
| nerlo-behavioral | Verified |
| nerlo-install-instruction | Unsafe |
| nerlo-multi-source | Verified |
| osv-scanner | Unsafe |
| trivy | Unsafe |
| trivy_image | unavailable |

| Severity | Findings |
| --- | --- |
| critical | 76 |
| high | 20 |
| medium | 24 |
| low | 15 |
| informational | 7 |

agents-md-generator is NOT recommended for integration: the scan surfaced 76 critical and 20 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering.

## 2. Source Provenance

- **Repository:** https://github.com/nushey/agents-md-generator
- **Commit scanned:** `unknown`
- **License:** MIT
- **Maintainer:** unknown
- **Version:** 0.5.5

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — unavailable / n/a

No findings.

### cisco-skill-scanner (v2.0.11) — Caution / 83.5

- **[low] Hidden data file detected** — Hidden file found: .agents-config.example.json. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.agents-config.example.json:None)
- **[low] Hidden data file detected** — Hidden file found: .agents-config.json. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.agents-config.json:None)
- **[medium] File extension does not match actual content type** — File 'CLAUDE.md' extension (.md) suggests one format but Magika detected a different text format: DOS batch file (batch). This may indicate content obfuscation or a misnamed file. (/repo/CLAUDE.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -LsSf https://astral.sh/uv/install.sh \| sh'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/INSTALLATION.md:2)
- **[informational] Vague skill description** — [mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -LsSf https://astral.sh/uv/install.sh \| sh'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/SKILL.md:2)
- **[informational] Vague skill description** — [mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation. (/repo/docs/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/docs/SKILL.md:None)
- **[informational] Vague skill description** — [mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation. (/repo/.github/SKILL.md:None)
- **[informational] Skill name does not follow agent skills naming rules** — Skill name '.github' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters. (/repo/.github/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/.github/SKILL.md:None)

### agent-audit-kit (v0.3.26) — Unsafe / 0.0

- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:5)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:5)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:5)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:5)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:12)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:18)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:19)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:20)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:21)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:22)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:23)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:24)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:25)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:29)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:29)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:29)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:29)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:29)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:32)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:32)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:33)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:33)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:33)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:34)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:34)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:38)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:38)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:38)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:32)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:19)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:42)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:42)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:43)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:43)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:43)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:43)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:34)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:44)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:44)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:43)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:44)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:45)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:45)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:43)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:19)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:50)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:50)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:20)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:21)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:52)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:52)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:52)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:5)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:57)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:50)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:32)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:59)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:60)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:34)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:61)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:67)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:67)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:67)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:67)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:68)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:68)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:77)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:77)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[critical] Agent instruction file contains shell command directives** — An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior. (AGENTS.md:None)
- **[medium] MCP tool logs caller-controlled input without CRLF/ANSI sanitization** — A '@tool'-decorated function parameter flows into logger.info / print / sys.stdout.write / console.log without stripping control characters (\r, \n, \x1b) first. CVE-2026-6494 (AAP MCP, CVSS 5.3 MEDIUM, CWE-117) lets an attacker forge log entries and inject ANSI escape sequences to socially engineer an operator. (src/agents_md_mcp/server.py:151)
- **[medium] Repo depends on a third-party agent-platform SDK** — The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel × Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants. (pyproject.toml:14)
- **[medium] Third-party GitHub Action not pinned by full commit SHA** — A workflow in '.github/workflows/' uses a third-party Action ('owner/action@ref') where 'ref' is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision — the downstream repo consuming it will happily run the new code with 'GITHUB_TOKEN' and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy. (.github/workflows/ci.yml:20)

### nerlo-behavioral (v0.1.0) — Verified / 100.0

No findings.

### nerlo-install-instruction (v0.1.0) — Unsafe / 59.0

- **[high] opt.nerlo-rules.nerlo-install-pipe-to-shell** — Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... \| bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders — the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal. (/repo/INSTALLATION.md:96)

### nerlo-multi-source (v0.1.0) — Verified / 100.0

No findings.

### trivy (v0.71.0) — Unsafe / 0.0

- **[high] Vulnerable OpenSSL included in cryptography wheels** — pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.  If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on  (uv.lock:None)
- **[medium] cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API** — cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7. (uv.lock:None)
- **[medium] python-idna: idna: Denial of Service via specially crafted long inputs** — Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as '"\u0660" * N' or '"\u30fb" * N + "\u6f22"' utilize the 'valid_contexto' function prior to length rejection, and for high values of 'N' will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi (uv.lock:None)
- **[high] MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal** — The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client (uv.lock:None)
- **[high] MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks** — The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2. (uv.lock:None)
- **[high] MCP Python SDK: WebSocket server transport does not support Host/Origin validation** — The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1. (uv.lock:None)
- **[medium] pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size** — \#\#\# Summary  'NestedSecretsSettingsSource' reads secret values from files in a configured 'secrets_dir'. When 'secrets_nested_subdir=True', a directory entry inside 'secrets_dir' that is a symbolic link pointing **outside** 'secrets_dir' is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented 'secrets_dir_max_size' protection. An attacker or lower-privileged component able to influence entries in the configured secrets dire (uv.lock:None)
- **[low] pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer** — A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. (uv.lock:None)
- **[high] python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens** — PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0. (uv.lock:None)
- **[medium] python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient** — PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame (uv.lock:None)
- **[medium] python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access** — PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv (uv.lock:None)
- **[medium] python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens** — PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled “work amplifier”: a (uv.lock:None)
- **[low] python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs** — PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be (uv.lock:None)
- **[medium] pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling** — pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges. (uv.lock:None)
- **[high] python-multipart: python-multipart: Denial of Service via excessive multipart part headers** — Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje (uv.lock:None)
- **[high] python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies** — Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne (uv.lock:None)
- **[medium] python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests** — Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted 'multipart/form-data' requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary. (uv.lock:None)
- **[low] multipart: Python-Multipart: Information disclosure via header parsing discrepancy** — Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 §4.2 explicitly forbid (uv.lock:None)
- **[low] python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling** — Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form  (uv.lock:None)
- **[low] python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory** — Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31. (uv.lock:None)
- **[high] starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows** — Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account’s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas (uv.lock:None)
- **[high] starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS** — Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply. (uv.lock:None)
- **[medium] starlette: Starlette: Security restriction bypass via malformed HTTP Host header** — Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP 'Host' request header was not validated before being used to reconstruct 'request.url'. Because the routing algorithm relies on the raw HTTP path while 'request.url' is rebuilt from the 'Host' header, a malformed header could make 'request.url.path' differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on 'request.url' (rather than the raw 'scope' path)  (uv.lock:None)
- **[medium] starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods** — Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo (uv.lock:None)
- **[low] starlette: Starlette: Information disclosure due to improper HTTP request path validation** — Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header  (uv.lock:None)

### osv-scanner (v2.3.8) — Unsafe / 0.0

- **[high] PYSEC-2026-2132 — PyPI click@8.3.1** — aliases: CVE-2026-7246, GHSA-47fr-3ffg-hgmw, PYSEC-2026-2132 \| CVSS: 7.2 (/repo/uv.lock:None)
- **[critical] PYSEC-2026-36 — PyPI cryptography@46.0.6** — aliases: CVE-2026-39892, GHSA-p423-j2cm-9vmq, PYSEC-2026-36 \| CVSS: 9.8 (/repo/uv.lock:None)
- **[high] GHSA-537c-gmf6-5ccf — PyPI cryptography@46.0.6** — aliases: GHSA-537c-gmf6-5ccf \| CVSS: 7.5 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-215 — PyPI idna@3.11** — aliases: CVE-2026-45409, GHSA-65pc-fj4g-8rjx, PYSEC-2026-215 \| CVSS: 6.9 (/repo/uv.lock:None)
- **[high] PYSEC-2026-3481 — PyPI mcp@1.26.0** — aliases: CVE-2026-52870, GHSA-hvrp-rf83-w775, PYSEC-2026-3481 \| CVSS: 7.6 (/repo/uv.lock:None)
- **[high] PYSEC-2026-3482 — PyPI mcp@1.26.0** — aliases: CVE-2026-52869, GHSA-jpw9-pfvf-9f58, PYSEC-2026-3482 \| CVSS: 7.1 (/repo/uv.lock:None)
- **[high] PYSEC-2026-3483 — PyPI mcp@1.26.0** — aliases: CVE-2026-59950, GHSA-vj7q-gjh5-988w, PYSEC-2026-3483 \| CVSS: 7.6 (/repo/uv.lock:None)
- **[medium] GHSA-4xgf-cpjx-pc3j — PyPI pydantic-settings@2.13.1** — aliases: CVE-2026-58203, GHSA-4xgf-cpjx-pc3j \| CVSS: 5.3 (/repo/uv.lock:None)
- **[low] PYSEC-2026-2987 — PyPI pygments@2.19.2** — aliases: CVE-2026-4539, GHSA-5239-wwwm-4pmq, PYSEC-2026-2987 \| CVSS: 3.3 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-175 — PyPI pyjwt@2.12.1** — aliases: CVE-2026-48522, GHSA-993g-76c3-p5m4, PYSEC-2026-175 \| CVSS: 4.2 (/repo/uv.lock:None)
- **[low] PYSEC-2026-177 — PyPI pyjwt@2.12.1** — aliases: CVE-2026-48524, GHSA-fhv5-28vv-h8m8, PYSEC-2026-177 \| CVSS: 3.7 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-178 — PyPI pyjwt@2.12.1** — aliases: CVE-2026-48525, GHSA-w7vc-732c-9m39, PYSEC-2026-178 \| CVSS: 5.3 (/repo/uv.lock:None)
- **[high] PYSEC-2026-179 — PyPI pyjwt@2.12.1** — aliases: CVE-2026-48526, GHSA-xgmm-8j9v-c9wx, PYSEC-2026-179 \| CVSS: 7.4 (/repo/uv.lock:None)
- **[medium] GHSA-jq35-7prp-9v3f — PyPI pyjwt@2.12.1** — aliases: CVE-2026-48523, GHSA-jq35-7prp-9v3f, PYSEC-2026-176 \| CVSS: 5.4 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-1845 — PyPI pytest@9.0.2** — aliases: CVE-2025-71176, GHSA-6w46-j5rx-g56g, PYSEC-2026-1845 \| CVSS: 6.8 (/repo/uv.lock:None)
- **[high] PYSEC-2026-3036 — PyPI python-multipart@0.0.22** — aliases: CVE-2026-53539, GHSA-5rvq-cxj2-64vf, PYSEC-2026-3036 \| CVSS: 7.5 (/repo/uv.lock:None)
- **[low] PYSEC-2026-3037 — PyPI python-multipart@0.0.22** — aliases: CVE-2026-53538, GHSA-6jv3-5f52-599m, PYSEC-2026-3037 \| CVSS: 3.7 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-3038 — PyPI python-multipart@0.0.22** — aliases: CVE-2026-40347, GHSA-mj87-hwqh-73pj, PYSEC-2026-3038 \| CVSS: 5.3 (/repo/uv.lock:None)
- **[high] PYSEC-2026-3039 — PyPI python-multipart@0.0.22** — aliases: CVE-2026-42561, GHSA-pp6c-gr5w-3c5g, PYSEC-2026-3039 \| CVSS: 7.5 (/repo/uv.lock:None)
- **[low] PYSEC-2026-3040 — PyPI python-multipart@0.0.22** — aliases: CVE-2026-53540, GHSA-v9pg-7xvm-68hf, PYSEC-2026-3040 \| CVSS: 3.7 (/repo/uv.lock:None)
- **[low] PYSEC-2026-3041 — PyPI python-multipart@0.0.22** — aliases: CVE-2026-53537, GHSA-vffw-93wf-4j4q, PYSEC-2026-3041 \| CVSS: 3.7 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-161 — PyPI starlette@1.0.0** — aliases: CVE-2026-48710, GHSA-86qp-5c8j-p5mr, PYSEC-2026-161, X41-2026-002 \| CVSS: 6.5 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-2280 — PyPI starlette@1.0.0** — aliases: CVE-2026-48817, GHSA-x746-7m8f-x49c, PYSEC-2026-2280 \| CVSS: 5.3 (/repo/uv.lock:None)
- **[high] PYSEC-2026-2281 — PyPI starlette@1.0.0** — aliases: CVE-2026-48818, GHSA-wqp7-x3pw-xc5r, PYSEC-2026-2281 \| CVSS: 7.5 (/repo/uv.lock:None)
- **[medium] PYSEC-2026-248 — PyPI starlette@1.0.0** — aliases: CVE-2026-54282, GHSA-jp82-jpqv-5vv3, PYSEC-2026-248 \| CVSS: 5.3 (/repo/uv.lock:None)
- **[high] PYSEC-2026-249 — PyPI starlette@1.0.0** — aliases: CVE-2026-54283, GHSA-82w8-qh3p-5jfq, PYSEC-2026-249 \| CVSS: 7.5 (/repo/uv.lock:None)

### trivy_image (v0.71.0) — unavailable / n/a

No findings.

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `02677b78-cba8-4578-85e8-e25b289619fb`
- **Completed:** 2026-08-02T10:27:43.092776+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:5b605cdef65aaf3d8b562c388cdd6483d6922974476d23c1f8e4f6c5f6ae723e`
- **AI decision log entries:** 3
  - `4e879ccd-b4f1-448b-97dd-5ed37e125d3e`
  - `2c218351-ac8c-4f7b-8e89-fd8370b04a3b`
  - `0840154f-3cfa-4d67-bbb7-1a30d9627c22`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.3128257120260969,
    "status": "not_applicable",
    "examined": null,
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": []
    },
    "display_score": null,
    "display_badge": "unavailable"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 83.5,
    "scanner_badge": "Caution",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.agents-config.example.json",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .agents-config.example.json. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.agents-config.json",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .agents-config.json. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "obfuscation",
        "file_path": "/repo/CLAUDE.md",
        "line_number": null,
        "rule_identifier": "FILE_MAGIC_MISMATCH",
        "title": "File extension does not match actual content type",
        "description": "File 'CLAUDE.md' extension (.md) suggests one format but Magika detected a different text format: DOS batch file (batch). This may indicate content obfuscation or a misnamed file.",
        "remediation": "Rename the file to match its actual content type, or remove it if it appears malicious."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/INSTALLATION.md",
        "line_number": 2,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -LsSf https://astral.sh/uv/install.sh | sh`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/SKILL.md",
        "line_number": 2,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -LsSf https://astral.sh/uv/install.sh | sh`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "social_engineering",
        "file_path": "/repo/docs/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/docs/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "social_engineering",
        "file_path": "/repo/.github/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "[mcp_server policy: capability-matches-purpose class; severity low -> informational] Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.github/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_INVALID_NAME",
        "title": "Skill name does not follow agent skills naming rules",
        "description": "Skill name '.github' is invalid. Agent skills require lowercase letters, numbers, and hyphens only, with a maximum length of 64 characters.",
        "remediation": "Rename the skill to match `[a-z0-9-]{1,64}` (e.g., 'pdf-processing')"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/.github/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      }
    ],
    "execution_duration_seconds": 15.300715669989586,
    "status": "complete",
    "examined": {
      "unit": "skills",
      "count": 3
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "repo",
        "docs",
        ".github"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 4,
        "high": 0,
        "medium": 1,
        "critical": 0,
        "informational": 7
      },
      "artifact_type_policy": "mcp_server",
      "downweighted_findings": 3
    },
    "display_score": 83.5,
    "display_badge": "Caution"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 5,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 5,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 5,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 5,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 12,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 18,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 19,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 20,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 21,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 22,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 23,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 24,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 25,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 29,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 29,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 29,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 29,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 29,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 32,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 32,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 33,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 33,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 33,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 34,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 34,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 38,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 38,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 38,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 32,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 19,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 42,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 42,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 43,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 43,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 43,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 43,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 34,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 44,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 44,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 43,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 44,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 45,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 45,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 43,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 19,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 50,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 50,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 20,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 21,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 52,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 52,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 52,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 5,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 57,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 50,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 32,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 59,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 60,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 34,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 61,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 67,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 67,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 67,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 67,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 68,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 68,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 77,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": 77,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "critical",
        "category": "agent-config",
        "file_path": "AGENTS.md",
        "line_number": null,
        "rule_identifier": "AAK-AGENT-001",
        "title": "Agent instruction file contains shell command directives",
        "description": "An agent instruction file (AGENTS.md, .cursorrules, CLAUDE.md) contains shell commands or execution directives that could be injected into agent behavior.",
        "remediation": "Remove shell commands from agent instruction files. Use proper tool definitions instead."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "taint-analysis",
        "file_path": "src/agents_md_mcp/server.py",
        "line_number": 151,
        "rule_identifier": "AAK-LOGINJ-001",
        "title": "MCP tool logs caller-controlled input without CRLF/ANSI sanitization",
        "description": "A `@tool`-decorated function parameter flows into logger.info / print / sys.stdout.write / console.log without stripping control characters (\\r, \\n, \\x1b) first. CVE-2026-6494 (AAP MCP, CVSS 5.3 MEDIUM, CWE-117) lets an attacker forge log entries and inject ANSI escape sequences to socially engineer an operator.",
        "remediation": "Strip \\r\\n\\x1b (or accept only printable ASCII) before logging anything derived from tool input. Prefer structured logging (JSON/logfmt) so log consumers aren't confused by forged lines."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": "pyproject.toml",
        "line_number": 14,
        "rule_identifier": "AAK-OAUTH-3P-001",
        "title": "Repo depends on a third-party agent-platform SDK",
        "description": "The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel \u00d7 Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants.",
        "remediation": "Pin the SDK to an exact version, audit the OAuth scopes it requests, and keep any deployment-level grants (Vercel, GCP, Workspace) in a secrets vault \u2014 never in a committed env file. See Vercel's bulletin for sensitive-env-var guidance: https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": ".github/workflows/ci.yml",
        "line_number": 20,
        "rule_identifier": "AAK-GHA-IMMUTABLE-001",
        "title": "Third-party GitHub Action not pinned by full commit SHA",
        "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
        "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
      }
    ],
    "execution_duration_seconds": 7.0485070690047,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 71
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 0,
        "high": 0,
        "medium": 3,
        "critical": 75,
        "informational": 0
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 32.364474411006086,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 23
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/exfiltration.yaml",
        "/opt/nerlo-rules/clipboard_exfiltration.yaml",
        "/opt/nerlo-rules/rce_endpoint.yaml",
        "/opt/nerlo-rules/taint_egress.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "merged_invocation": true
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 59.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "high",
        "category": "install-instruction-exec",
        "file_path": "/repo/INSTALLATION.md",
        "line_number": 96,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 32.364426390005974,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 22
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/install_instructions.yaml",
        "/opt/nerlo-rules/cursor_rules.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "severity_counts": {
        "low": 0,
        "high": 1,
        "medium": 0,
        "critical": 0,
        "informational": 0
      },
      "merged_invocation": true
    },
    "display_score": 59.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-multi-source",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 23.06895843500388,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "nerlo-original",
      "per_source": [
        {
          "badge": "Verified",
          "label": "pypi@0.5.5",
          "score": 100.0,
          "version": "0.5.5",
          "identifier": "agents-md-generator",
          "provenance": "clean",
          "source_type": "pypi",
          "artifact_type": "mcp_server",
          "finding_count": 0,
          "malware_status": "complete",
          "injected_rule_ids": []
        }
      ],
      "report_type": "nerlo-multi-source",
      "diverged_sources": [],
      "published_surfaces_scanned": 1
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "trivy",
    "scanner_version": "0.71.0",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "GHSA-537c-gmf6-5ccf",
        "title": "Vulnerable OpenSSL included in cryptography wheels",
        "description": "pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue. More details about the vulnerability itself can be found in https://openssl-library.org/news/secadv/20260609.txt.\n\nIf you are building cryptography source (\"sdist\") then you are responsible for upgrading your copy of OpenSSL. Only users installing from wheels built by the cryptography project (i.e., those distributed on ",
        "remediation": "Upgrade cryptography from 46.0.6 to 48.0.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-39892",
        "title": "cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API",
        "description": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.",
        "remediation": "Upgrade cryptography from 46.0.6 to 46.0.7 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-45409",
        "title": "python-idna: idna: Denial of Service via specially crafted long inputs",
        "description": "Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fi",
        "remediation": "Upgrade idna from 3.11 to 3.15 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-52869",
        "title": "MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal",
        "description": "The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client",
        "remediation": "Upgrade mcp from 1.26.0 to 1.27.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-52870",
        "title": "MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks",
        "description": "The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.",
        "remediation": "Upgrade mcp from 1.26.0 to 1.27.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-59950",
        "title": "MCP Python SDK: WebSocket server transport does not support Host/Origin validation",
        "description": "The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.",
        "remediation": "Upgrade mcp from 1.26.0 to 1.28.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "GHSA-4xgf-cpjx-pc3j",
        "title": "pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size",
        "description": "### Summary\n\n`NestedSecretsSettingsSource` reads secret values from files in a configured `secrets_dir`. When `secrets_nested_subdir=True`, a directory entry inside `secrets_dir` that is a symbolic link pointing **outside** `secrets_dir` is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented `secrets_dir_max_size` protection. An attacker or lower-privileged component able to influence entries in the configured secrets dire",
        "remediation": "Upgrade pydantic-settings from 2.13.1 to 2.14.2 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-4539",
        "title": "pygments: Pygments: Denial of Service via inefficient regular expression processing in AdlLexer",
        "description": "A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
        "remediation": "Upgrade pygments from 2.19.2 to 2.20.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48526",
        "title": "python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens",
        "description": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.",
        "remediation": "Upgrade pyjwt from 2.12.1 to 2.13.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48522",
        "title": "python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient",
        "description": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application's jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parame",
        "remediation": "Upgrade pyjwt from 2.12.1 to 2.13.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48523",
        "title": "python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access",
        "description": "PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv",
        "remediation": "Upgrade pyjwt from 2.12.1 to 2.13.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48525",
        "title": "python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens",
        "description": "PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option (\"b64\": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules. For b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provided detached_payload. In practice, this turns the middle segment into an attacker-controlled \u201cwork amplifier\u201d: a",
        "remediation": "Upgrade pyjwt from 2.12.1 to 2.13.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48524",
        "title": "python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs",
        "description": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be",
        "remediation": "Upgrade pyjwt from 2.12.1 to 2.13.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2025-71176",
        "title": "pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling",
        "description": "pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.",
        "remediation": "Upgrade pytest from 9.0.2 to 9.0.3 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-42561",
        "title": "python-multipart: python-multipart: Denial of Service via excessive multipart part headers",
        "description": "Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request reje",
        "remediation": "Upgrade python-multipart from 0.0.22 to 0.0.27 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-53539",
        "title": "python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies",
        "description": "Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the ne",
        "remediation": "Upgrade python-multipart from 0.0.22 to 0.0.30 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-40347",
        "title": "python-multipart: Python-Multipart: Denial of Service via crafted multipart/form-data requests",
        "description": "Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.",
        "remediation": "Upgrade python-multipart from 0.0.22 to 0.0.26 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-53537",
        "title": "multipart: Python-Multipart: Information disclosure via header parsing discrepancy",
        "description": "Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 \u00a74.2 explicitly forbid",
        "remediation": "Upgrade python-multipart from 0.0.22 to 0.0.30 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-53538",
        "title": "python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling",
        "description": "Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form ",
        "remediation": "Upgrade python-multipart from 0.0.22 to 0.0.30 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-53540",
        "title": "python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory",
        "description": "Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.",
        "remediation": "Upgrade python-multipart from 0.0.22 to 0.0.31 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48818",
        "title": "starlette: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows",
        "description": "Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\\\attacker.com\\share can cause os.path.realpath to initiate an outbound SMB connection before the path is rejected, exposing the service account\u2019s NTLMv2 credentials for offline cracking or relay even though the HTTP response is only a 404. The issue affects default follow_symlink=False deployments, including frameworks built on Starlette such as Fas",
        "remediation": "Upgrade starlette from 1.0.0 to 1.1.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "high",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-54283",
        "title": "starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS",
        "description": "Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply.",
        "remediation": "Upgrade starlette from 1.0.0 to 1.3.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48710",
        "title": "starlette: Starlette: Security restriction bypass via malformed HTTP Host header",
        "description": "Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) ",
        "remediation": "Upgrade starlette from 1.0.0 to 1.0.1 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "medium",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-48817",
        "title": "starlette: Starlette: Information disclosure and unintended method execution via non-standard HTTP methods",
        "description": "Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lo",
        "remediation": "Upgrade starlette from 1.0.0 to 1.1.0 or later"
      },
      {
        "tool_name": "trivy",
        "severity": "low",
        "category": "uv",
        "file_path": "uv.lock",
        "line_number": null,
        "rule_identifier": "CVE-2026-54282",
        "title": "starlette: Starlette: Information disclosure due to improper HTTP request path validation",
        "description": "Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header ",
        "remediation": "Upgrade starlette from 1.0.0 to 1.3.0 or later"
      }
    ],
    "execution_duration_seconds": 0.8998611849965528,
    "status": "complete",
    "examined": {
      "unit": "manifests",
      "count": 1
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
      "report_type": "filesystem-vulnerability",
      "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
      "severity_counts": {
        "low": 6,
        "high": 9,
        "medium": 10,
        "critical": 0,
        "informational": 0
      },
      "manifests_scanned": [
        "uv.lock"
      ]
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "osv-scanner",
    "scanner_version": "2.3.8",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-2132",
        "title": "PYSEC-2026-2132 \u2014 PyPI click@8.3.1",
        "description": "aliases: CVE-2026-7246, GHSA-47fr-3ffg-hgmw, PYSEC-2026-2132 | CVSS: 7.2",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "critical",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-36",
        "title": "PYSEC-2026-36 \u2014 PyPI cryptography@46.0.6",
        "description": "aliases: CVE-2026-39892, GHSA-p423-j2cm-9vmq, PYSEC-2026-36 | CVSS: 9.8",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "GHSA-537c-gmf6-5ccf",
        "title": "GHSA-537c-gmf6-5ccf \u2014 PyPI cryptography@46.0.6",
        "description": "aliases: GHSA-537c-gmf6-5ccf | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-215",
        "title": "PYSEC-2026-215 \u2014 PyPI idna@3.11",
        "description": "aliases: CVE-2026-45409, GHSA-65pc-fj4g-8rjx, PYSEC-2026-215 | CVSS: 6.9",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3481",
        "title": "PYSEC-2026-3481 \u2014 PyPI mcp@1.26.0",
        "description": "aliases: CVE-2026-52870, GHSA-hvrp-rf83-w775, PYSEC-2026-3481 | CVSS: 7.6",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3482",
        "title": "PYSEC-2026-3482 \u2014 PyPI mcp@1.26.0",
        "description": "aliases: CVE-2026-52869, GHSA-jpw9-pfvf-9f58, PYSEC-2026-3482 | CVSS: 7.1",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3483",
        "title": "PYSEC-2026-3483 \u2014 PyPI mcp@1.26.0",
        "description": "aliases: CVE-2026-59950, GHSA-vj7q-gjh5-988w, PYSEC-2026-3483 | CVSS: 7.6",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "GHSA-4xgf-cpjx-pc3j",
        "title": "GHSA-4xgf-cpjx-pc3j \u2014 PyPI pydantic-settings@2.13.1",
        "description": "aliases: CVE-2026-58203, GHSA-4xgf-cpjx-pc3j | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-2987",
        "title": "PYSEC-2026-2987 \u2014 PyPI pygments@2.19.2",
        "description": "aliases: CVE-2026-4539, GHSA-5239-wwwm-4pmq, PYSEC-2026-2987 | CVSS: 3.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-175",
        "title": "PYSEC-2026-175 \u2014 PyPI pyjwt@2.12.1",
        "description": "aliases: CVE-2026-48522, GHSA-993g-76c3-p5m4, PYSEC-2026-175 | CVSS: 4.2",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-177",
        "title": "PYSEC-2026-177 \u2014 PyPI pyjwt@2.12.1",
        "description": "aliases: CVE-2026-48524, GHSA-fhv5-28vv-h8m8, PYSEC-2026-177 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-178",
        "title": "PYSEC-2026-178 \u2014 PyPI pyjwt@2.12.1",
        "description": "aliases: CVE-2026-48525, GHSA-w7vc-732c-9m39, PYSEC-2026-178 | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-179",
        "title": "PYSEC-2026-179 \u2014 PyPI pyjwt@2.12.1",
        "description": "aliases: CVE-2026-48526, GHSA-xgmm-8j9v-c9wx, PYSEC-2026-179 | CVSS: 7.4",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "GHSA-jq35-7prp-9v3f",
        "title": "GHSA-jq35-7prp-9v3f \u2014 PyPI pyjwt@2.12.1",
        "description": "aliases: CVE-2026-48523, GHSA-jq35-7prp-9v3f, PYSEC-2026-176 | CVSS: 5.4",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-1845",
        "title": "PYSEC-2026-1845 \u2014 PyPI pytest@9.0.2",
        "description": "aliases: CVE-2025-71176, GHSA-6w46-j5rx-g56g, PYSEC-2026-1845 | CVSS: 6.8",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3036",
        "title": "PYSEC-2026-3036 \u2014 PyPI python-multipart@0.0.22",
        "description": "aliases: CVE-2026-53539, GHSA-5rvq-cxj2-64vf, PYSEC-2026-3036 | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3037",
        "title": "PYSEC-2026-3037 \u2014 PyPI python-multipart@0.0.22",
        "description": "aliases: CVE-2026-53538, GHSA-6jv3-5f52-599m, PYSEC-2026-3037 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3038",
        "title": "PYSEC-2026-3038 \u2014 PyPI python-multipart@0.0.22",
        "description": "aliases: CVE-2026-40347, GHSA-mj87-hwqh-73pj, PYSEC-2026-3038 | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3039",
        "title": "PYSEC-2026-3039 \u2014 PyPI python-multipart@0.0.22",
        "description": "aliases: CVE-2026-42561, GHSA-pp6c-gr5w-3c5g, PYSEC-2026-3039 | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3040",
        "title": "PYSEC-2026-3040 \u2014 PyPI python-multipart@0.0.22",
        "description": "aliases: CVE-2026-53540, GHSA-v9pg-7xvm-68hf, PYSEC-2026-3040 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "low",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-3041",
        "title": "PYSEC-2026-3041 \u2014 PyPI python-multipart@0.0.22",
        "description": "aliases: CVE-2026-53537, GHSA-vffw-93wf-4j4q, PYSEC-2026-3041 | CVSS: 3.7",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-161",
        "title": "PYSEC-2026-161 \u2014 PyPI starlette@1.0.0",
        "description": "aliases: CVE-2026-48710, GHSA-86qp-5c8j-p5mr, PYSEC-2026-161, X41-2026-002 | CVSS: 6.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-2280",
        "title": "PYSEC-2026-2280 \u2014 PyPI starlette@1.0.0",
        "description": "aliases: CVE-2026-48817, GHSA-x746-7m8f-x49c, PYSEC-2026-2280 | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-2281",
        "title": "PYSEC-2026-2281 \u2014 PyPI starlette@1.0.0",
        "description": "aliases: CVE-2026-48818, GHSA-wqp7-x3pw-xc5r, PYSEC-2026-2281 | CVSS: 7.5",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "medium",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-248",
        "title": "PYSEC-2026-248 \u2014 PyPI starlette@1.0.0",
        "description": "aliases: CVE-2026-54282, GHSA-jp82-jpqv-5vv3, PYSEC-2026-248 | CVSS: 5.3",
        "remediation": null
      },
      {
        "tool_name": "osv-scanner",
        "severity": "high",
        "category": "PyPI",
        "file_path": "/repo/uv.lock",
        "line_number": null,
        "rule_identifier": "PYSEC-2026-249",
        "title": "PYSEC-2026-249 \u2014 PyPI starlette@1.0.0",
        "description": "aliases: CVE-2026-54283, GHSA-82w8-qh3p-5jfq, PYSEC-2026-249 | CVSS: 7.5",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 3.4831560809980147,
    "status": "complete",
    "examined": {
      "unit": "manifests",
      "count": 1
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
      "report_type": "osv-vulnerability",
      "ecosystems_seen": [
        "PyPI"
      ],
      "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
      "severity_counts": {
        "low": 5,
        "high": 10,
        "medium": 10,
        "critical": 1,
        "informational": 0
      },
      "manifests_scanned": [
        "/repo/uv.lock"
      ],
      "finding_id_aliases": {
        "PYSEC-2026-36": [
          "CVE-2026-39892",
          "GHSA-p423-j2cm-9vmq"
        ],
        "PYSEC-2026-161": [
          "CVE-2026-48710",
          "GHSA-86qp-5c8j-p5mr",
          "X41-2026-002"
        ],
        "PYSEC-2026-175": [
          "CVE-2026-48522",
          "GHSA-993g-76c3-p5m4"
        ],
        "PYSEC-2026-177": [
          "CVE-2026-48524",
          "GHSA-fhv5-28vv-h8m8"
        ],
        "PYSEC-2026-178": [
          "CVE-2026-48525",
          "GHSA-w7vc-732c-9m39"
        ],
        "PYSEC-2026-179": [
          "CVE-2026-48526",
          "GHSA-xgmm-8j9v-c9wx"
        ],
        "PYSEC-2026-215": [
          "CVE-2026-45409",
          "GHSA-65pc-fj4g-8rjx"
        ],
        "PYSEC-2026-248": [
          "CVE-2026-54282",
          "GHSA-jp82-jpqv-5vv3"
        ],
        "PYSEC-2026-249": [
          "CVE-2026-54283",
          "GHSA-82w8-qh3p-5jfq"
        ],
        "PYSEC-2026-1845": [
          "CVE-2025-71176",
          "GHSA-6w46-j5rx-g56g"
        ],
        "PYSEC-2026-2132": [
          "CVE-2026-7246",
          "GHSA-47fr-3ffg-hgmw"
        ],
        "PYSEC-2026-2280": [
          "CVE-2026-48817",
          "GHSA-x746-7m8f-x49c"
        ],
        "PYSEC-2026-2281": [
          "CVE-2026-48818",
          "GHSA-wqp7-x3pw-xc5r"
        ],
        "PYSEC-2026-2987": [
          "CVE-2026-4539",
          "GHSA-5239-wwwm-4pmq"
        ],
        "PYSEC-2026-3036": [
          "CVE-2026-53539",
          "GHSA-5rvq-cxj2-64vf"
        ],
        "PYSEC-2026-3037": [
          "CVE-2026-53538",
          "GHSA-6jv3-5f52-599m"
        ],
        "PYSEC-2026-3038": [
          "CVE-2026-40347",
          "GHSA-mj87-hwqh-73pj"
        ],
        "PYSEC-2026-3039": [
          "CVE-2026-42561",
          "GHSA-pp6c-gr5w-3c5g"
        ],
        "PYSEC-2026-3040": [
          "CVE-2026-53540",
          "GHSA-v9pg-7xvm-68hf"
        ],
        "PYSEC-2026-3041": [
          "CVE-2026-53537",
          "GHSA-vffw-93wf-4j4q"
        ],
        "PYSEC-2026-3481": [
          "CVE-2026-52870",
          "GHSA-hvrp-rf83-w775"
        ],
        "PYSEC-2026-3482": [
          "CVE-2026-52869",
          "GHSA-jpw9-pfvf-9f58"
        ],
        "PYSEC-2026-3483": [
          "CVE-2026-59950",
          "GHSA-vj7q-gjh5-988w"
        ],
        "GHSA-4xgf-cpjx-pc3j": [
          "CVE-2026-58203"
        ],
        "GHSA-jq35-7prp-9v3f": [
          "CVE-2026-48523",
          "PYSEC-2026-176"
        ]
      },
      "cross_scanner_correlation": {
        "only_osv": [
          "PYSEC-2026-2132"
        ],
        "only_trivy": [],
        "intersection_ids": [
          "CVE-2025-71176",
          "CVE-2026-39892",
          "CVE-2026-40347",
          "CVE-2026-42561",
          "CVE-2026-4539",
          "CVE-2026-45409",
          "CVE-2026-48522",
          "CVE-2026-48523",
          "CVE-2026-48524",
          "CVE-2026-48525",
          "CVE-2026-48526",
          "CVE-2026-48710",
          "CVE-2026-48817",
          "CVE-2026-48818",
          "CVE-2026-52869",
          "CVE-2026-52870",
          "CVE-2026-53537",
          "CVE-2026-53538",
          "CVE-2026-53539",
          "CVE-2026-53540",
          "CVE-2026-54282",
          "CVE-2026-54283",
          "CVE-2026-59950",
          "GHSA-4xgf-cpjx-pc3j",
          "GHSA-537c-gmf6-5ccf"
        ]
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "trivy_image",
    "scanner_version": "0.71.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 3.8700003642588854e-05,
    "status": "not_applicable",
    "examined": {
      "unit": "image_targets",
      "count": 0
    },
    "metadata": {
      "reason": "no OCI image acquired for this artifact"
    },
    "display_score": null,
    "display_badge": "unavailable"
  }
]
```
