# Security Audit Report — mcp-hetzner

- **Report ID:** `e264ba91-2413-4d62-bcbb-c2209c5e7b57`
- **Generated:** 2026-07-22T02:11:04.363478+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Verified (composite)  
**Security score:** 87.55

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | unavailable |
| bearer | Verified |
| cisco-skill-scanner | Unsafe |
| nerlo-behavioral | Verified |
| nerlo-install-instruction | Verified |
| osv-scanner | unavailable |
| trivy | Verified |

| Severity | Findings |
| --- | --- |
| critical | 0 |
| high | 2 |
| medium | 18 |
| low | 2 |

mcp-hetzner may be integrated with compensating controls: review the 2 high-severity findings below, restrict granted permissions to the minimum the manifest declares, and subscribe to monitoring alerts for score changes.

## 2. Source Provenance

- **Repository:** https://github.com/dkruyt/mcp-hetzner
- **Commit scanned:** `unknown`
- **License:** MIT
- **Maintainer:** Dennis Kruyt
- **Version:** 0.1.0

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — unavailable / n/a

No findings.

### cisco-skill-scanner (v2.0.11) — Unsafe / 17.5

- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography: ‍ (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography: ‍ (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography: ‍ (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography: ‍ (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography: ‍ (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:   (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)
- **[medium] UNICODE STEGANOGRAPHY detected by YARA** — Detects hidden Unicode characters used for invisible prompt injection and steganography:  (/repo/media/mcp-hetzner.gif:0)

### agent-audit-kit (v0.3.26) — Unsafe / 58.0

- **[high] Generic high-entropy secret** — A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key. (mcp_hetzner/example.py:23)
- **[high] Generic high-entropy secret** — A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key. (mcp_hetzner/server.py:36)
- **[medium] No lockfile present** — A package manifest exists but no lockfile was found. Without lockfiles, dependency versions float and can be silently updated. (pyproject.toml:None)
- **[low] MCP server repo missing SECURITY.md or security_contact** — A repository whose name or pyproject keywords declare it as an MCP server ships without a top-level SECURITY.md AND without a 'security_contact' entry in marketplace.json / pyproject.toml / package.json. Anthropic's April 2026 SECURITY.md guidance makes this the baseline expectation so researchers have a channel. (SECURITY.md:None)
- **[medium] Repo depends on a third-party agent-platform SDK** — The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel × Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants. (pyproject.toml:6)

### bearer (v2.0.2) — Verified / 100.0

No findings.

### nerlo-behavioral (v0.1.0) — Verified / 100.0

No findings.

### nerlo-install-instruction (v0.1.0) — Verified / 100.0

No findings.

### trivy (v0.71.0) — Verified / 100.0

No findings.

### osv-scanner (v2.3.8) — unavailable / n/a

No findings.

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `cd86f704-3823-4882-a25b-d52c394f422e`
- **Completed:** 2026-07-21T02:35:20.285381+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:d40988d18b88a65a7f0868915e1c7b2a3c6cdf062b2f3bdac6e9d0920f9670e1`
- **AI decision log entries:** 1
  - `d223e46d-2bd3-4eae-852c-0d99c75f69c7`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 1.0973667750076856,
    "status": "not_applicable",
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": []
    },
    "display_score": null,
    "display_badge": "unavailable"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 17.5,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u200d",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u200d",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u200d",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u200d",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u200d",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: \u2029",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "medium",
        "category": "unicode_steganography",
        "file_path": "/repo/media/mcp-hetzner.gif",
        "line_number": 0,
        "rule_identifier": "YARA_prompt_injection_unicode_steganography",
        "title": "UNICODE STEGANOGRAPHY detected by YARA",
        "description": "Detects hidden Unicode characters used for invisible prompt injection and steganography: ",
        "remediation": "Review and remove unicode steganography pattern"
      }
    ],
    "execution_duration_seconds": 26.666732358004083,
    "status": "complete",
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "repo"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 1,
        "high": 0,
        "medium": 16,
        "critical": 0,
        "informational": 1
      }
    },
    "display_score": 17.5,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 58.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "mcp_hetzner/example.py",
        "line_number": 23,
        "rule_identifier": "AAK-SECRET-004",
        "title": "Generic high-entropy secret",
        "description": "A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key.",
        "remediation": "Move to environment variables or secrets manager."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "secret-exposure",
        "file_path": "mcp_hetzner/server.py",
        "line_number": 36,
        "rule_identifier": "AAK-SECRET-004",
        "title": "Generic high-entropy secret",
        "description": "A value assigned to a secret-like key has high Shannon entropy, indicating a likely credential or API key.",
        "remediation": "Move to environment variables or secrets manager."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": "pyproject.toml",
        "line_number": null,
        "rule_identifier": "AAK-SUPPLY-004",
        "title": "No lockfile present",
        "description": "A package manifest exists but no lockfile was found. Without lockfiles, dependency versions float and can be silently updated.",
        "remediation": "Generate and commit lockfile."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "low",
        "category": "supply-chain",
        "file_path": "SECURITY.md",
        "line_number": null,
        "rule_identifier": "AAK-SEC-MD-001",
        "title": "MCP server repo missing SECURITY.md or security_contact",
        "description": "A repository whose name or pyproject keywords declare it as an MCP server ships without a top-level SECURITY.md AND without a `security_contact` entry in marketplace.json / pyproject.toml / package.json. Anthropic's April 2026 SECURITY.md guidance makes this the baseline expectation so researchers have a channel.",
        "remediation": "Add SECURITY.md at the repo root with a disclosure email and response SLA; OR add `security_contact` to the project manifest."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": "pyproject.toml",
        "line_number": 6,
        "rule_identifier": "AAK-OAUTH-3P-001",
        "title": "Repo depends on a third-party agent-platform SDK",
        "description": "The project depends on an agent-platform SDK (context-ai, langsmith, helicone, langfuse, humanloop, MCP SDK). Informational finding so reviewers audit the vendor's OAuth-scope footprint before merging. Raised to MEDIUM because the April 19 2026 Vercel \u00d7 Context.ai incident showed a single vendor compromise can turn into a production breach via transitive OAuth grants.",
        "remediation": "Pin the SDK to an exact version, audit the OAuth scopes it requests, and keep any deployment-level grants (Vercel, GCP, Workspace) in a secrets vault \u2014 never in a committed env file. See Vercel's bulletin for sensitive-env-var guidance: https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"
      }
    ],
    "execution_duration_seconds": 17.114162287005456,
    "status": "complete",
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "files_scanned": 10,
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 1,
        "high": 2,
        "medium": 2,
        "critical": 0,
        "informational": 0
      }
    },
    "display_score": 58.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "bearer",
    "scanner_version": "2.0.2",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 12.376686654999503,
    "status": "complete",
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/Bearer/bearer",
      "report_type": "security",
      "rules_loaded": 1,
      "install_command": "curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /usr/local/bin \"v2.0.2\""
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 43.72404219600139,
    "status": "complete",
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "files_scanned": 5,
      "install_command": "pip install 'semgrep==1.97.0'"
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 43.333969925995916,
    "status": "complete",
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "files_scanned": 1,
      "install_command": "pip install 'semgrep==1.97.0'"
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "trivy",
    "scanner_version": "0.71.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.8052911999984644,
    "status": "complete",
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
      "report_type": "filesystem-vulnerability",
      "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
      "manifests_scanned": []
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "osv-scanner",
    "scanner_version": "2.3.8",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 1.0027067930059275,
    "status": "not_applicable",
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
      "report_type": "osv-vulnerability",
      "ecosystems_seen": [],
      "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
      "manifests_scanned": [],
      "finding_id_aliases": {},
      "cross_scanner_correlation": {
        "only_osv": [],
        "only_trivy": [],
        "intersection_ids": []
      }
    },
    "display_score": null,
    "display_badge": "unavailable"
  }
]
```
