{
  "ml": {
    "v": "7",
    "id": 1234,
    "lvl": -1,
    "conf": 0,
    "prob": 0.000009934107765730005,
    "type": "shell",
    "version": "v18.18",
    "analyzed_at": "2026-09-23T20:27:08Z"
  },
  "path": "actions@9f6c88d6bc9e9d8416282b1f88be43758b0d066a",
  "raw": {
    "rev": "a041b",
    "files": [
      {
        "id": 1710,
        "ctx": [
          {
            "b": "abZy80000000zNJ}=zJw/8soK-y8Xd2Uoy-p^Vc[xU{vp:R7]DCyYEEQ(?=6or63qMu-D6[7%FW^(4+f\u003eYRP0ISGcsD/@ciJn$inD]I",
            "ln": 0
          }
        ],
        "mol": "O₃(AsCaS₂)H₅(Cm₇Db₂F₇Os₃Po)Md₃(Bk₅Pa₂)",
        "pid": 6,
        "rel": "fetched",
        "sha": "44ec9c7e79c1240ff91c53a1535eb52d138f2d98fce0eeb2ef593c394a4b96a7",
        "via": "https://codeload.github.com/regclient/actions/tar.gz/9f6c88d6bc9e9d8416282b1f88be43758b0d066a",
        "path": "pkg:github/regclient/actions@9f6c88d6bc9e9d8416282b1f88be43758b0d066a",
        "risk": 19,
        "size": 15901,
        "type": "gz",
        "depth": 2,
        "facts": {
          "metrics": {
            "file": {
              "size": 15901,
              "entropy": 7.98
            },
            "binary": {
              "peak_region_bytes": 15901,
              "peak_region_entropy": 7.82
            }
          }
        },
        "traits": [
          {
            "id": "metadata/lang/natural::lang-english--atom-5",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"for\"",
            "from": [
              {
                "file": 13
              }
            ]
          },
          {
            "id": "micro-behaviors/process/create/shell/git::github-actions-git-tag",
            "conf": 0.9,
            "crit": 3,
            "desc": "GitHub Actions creates a git tag"
          },
          {
            "id": "metadata/build/ci/github-actions::workflow-definition-path",
            "conf": 0.99,
            "crit": 3,
            "desc": "GitHub Actions workflow definition path",
            "from": [
              {
                "file": 17
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/services/github::github-rest-json-accept-header",
            "conf": 0.95,
            "crit": 3,
            "desc": "GitHub REST JSON API Accept header",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "objectives/supply-chain/trojanized/build-pipeline::gha-release-publish-step",
            "atk": "T1195.002",
            "conf": 0.86,
            "crit": 3,
            "desc": "GitHub Actions package publish step",
            "from": [
              {
                "file": 17
              }
            ]
          },
          {
            "id": "metadata/build/ci/permission::job-contents-write-permission",
            "conf": 0.92,
            "crit": 3,
            "desc": "Job grants contents write permission"
          },
          {
            "id": "micro-behaviors/process/create/shell/git::github-actions-git-push",
            "conf": 0.9,
            "crit": 3,
            "desc": "GitHub Actions pushes a git ref"
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl-silent-fail-flags-text",
            "atk": "T1105",
            "conf": 0.86,
            "crit": 3,
            "desc": "curl text contains silent or fail flags",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "objectives/anti-static/obfuscation/code-metrics/structure::sh-dense-eval-chains-unless-cond-1--rx-3",
            "atk": "T1027",
            "mbc": "B0032",
            "conf": 0.92,
            "crit": 3,
            "desc": "Command-line usage text marker",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/package/documentation/agent-safety::security-markdown-basename",
            "conf": 0.94,
            "crit": 3,
            "desc": "Security documentation markdown file",
            "from": [
              {
                "file": 12
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::curl-wget-command",
            "atk": "T1105",
            "conf": 0.96,
            "crit": 3,
            "desc": "Shell invokes curl or wget",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              },
              {
                "off": 1713,
                "file": 1732,
                "line": 74
              }
            ],
            "uses": [
              34
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-1",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"the\"",
            "from": [
              {
                "file": 12
              }
            ]
          },
          {
            "id": "metadata/file/string/cicd::github-workflow-file-path",
            "conf": 0.98,
            "crit": 3,
            "desc": "GitHub Actions workflow file path",
            "from": [
              {
                "file": 17
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl-cmd",
            "atk": "T1105",
            "conf": 0.7,
            "crit": 2,
            "desc": "curl command includes URL or option",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/build/ci/secret::checkout-persisted-credentials",
            "conf": 0.96,
            "crit": 3,
            "desc": "Checkout persists Git credentials on disk"
          },
          {
            "id": "micro-behaviors/fs/directory/chdir::shell-change-directory",
            "conf": 0.95,
            "crit": 3,
            "desc": "Shell changes working directory",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::fetch-output-flag-structured-file",
            "conf": 0.84,
            "crit": 3,
            "desc": "Structured file has curl/wget output path",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::shell-curl-url-call",
            "atk": "T1105",
            "conf": 0.8,
            "crit": 3,
            "desc": "curl call names an HTTP URL",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/file/extension/identity::shell-a",
            "conf": 1.0,
            "crit": 2,
            "desc": "POSIX shell script extension",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/services/github::github-api-host",
            "conf": 0.86,
            "crit": 3,
            "desc": "GitHub API host reference",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-7",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"this\"",
            "from": [
              {
                "file": 12
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/path/temp::tmp-path-content",
            "conf": 1.0,
            "crit": 2,
            "desc": "Contains a /tmp/ or /var/tmp/ path",
            "from": [
              {
                "file": 21
              }
            ]
          },
          {
            "id": "micro-behaviors/process/create/shell/git::github-actions-git-tag-and-push",
            "conf": 0.94,
            "crit": 3,
            "desc": "GitHub Actions creates and pushes a tag",
            "from": [
              {
                "file": 1731
              }
            ],
            "uses": [
              1,
              6
            ]
          },
          {
            "id": "metadata/file/catalog/service::service-name-github",
            "conf": 0.6,
            "crit": 3,
            "desc": "GitHub service name",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/authorization-header::bearer-prefix",
            "atk": "T1071.001",
            "mbc": "C0002",
            "conf": 0.72,
            "crit": 3,
            "desc": "HTTP Bearer authorization header prefix",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/build/ci/step::gha-remote-docker-image",
            "conf": 0.92,
            "crit": 3,
            "desc": "Action pulls a remote Docker image",
            "from": [
              {
                "file": 17
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/search::grep-keyword",
            "conf": 0.7,
            "crit": 1,
            "desc": "Contains the grep command keyword",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-6",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"with\"",
            "from": [
              {
                "file": 14
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-4",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"have\"",
            "from": [
              {
                "file": 25
              }
            ]
          },
          {
            "id": "metadata/build/ci/trigger::scheduled-workflow-trigger",
            "conf": 0.9,
            "crit": 3,
            "desc": "GitHub scheduled workflow trigger"
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-2",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"and\"",
            "from": [
              {
                "file": 12
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/chmod/executable/mode::chmod-exec-var-target",
            "atk": "T1222",
            "mbc": "E1222",
            "conf": 0.9,
            "crit": 3,
            "desc": "chmod marks a variable path executable",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "objectives/supply-chain/hidden-payload/ci::gha-action-yml-manifest",
            "atk": "T1195.002",
            "conf": 0.98,
            "crit": 3,
            "desc": "GitHub Action action.yml manifest",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "metadata/package/documentation/source::readme-markdown-basename",
            "conf": 0.99,
            "crit": 2,
            "desc": "README Markdown basename",
            "from": [
              {
                "file": 14
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::curl-command-call",
            "atk": "T1105",
            "conf": 0.96,
            "crit": 3,
            "desc": "Shell invokes the curl command",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-3",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"that\"",
            "from": [
              {
                "file": 25
              }
            ]
          },
          {
            "id": "metadata/build/ci/step::composite-action-type",
            "conf": 1.0,
            "crit": 3,
            "desc": "GitHub Actions composite action definition"
          },
          {
            "id": "micro-behaviors/communications/http/url/forge::public-code-forge-url",
            "conf": 0.9,
            "crit": 3,
            "desc": "References a public code-forge URL",
            "from": [
              {
                "file": 12
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::fetch-command-with-var",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "curl or wget references shell variable",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl",
            "atk": "T1105",
            "conf": 0.66,
            "crit": 3,
            "desc": "Download via curl",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              },
              {
                "file": 1732
              }
            ],
            "uses": [
              13
            ]
          },
          {
            "id": "micro-behaviors/communications/http/services/github::github-rest-api-version-header",
            "conf": 0.9,
            "crit": 3,
            "desc": "GitHub REST API version header",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl-silent",
            "atk": "T1105",
            "conf": 0.92,
            "crit": 3,
            "desc": "curl command uses silent or fail flags",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              },
              {
                "off": 1713,
                "file": 1732,
                "line": 74
              }
            ],
            "uses": [
              7,
              34
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::fetch-command-position-script",
            "conf": 0.9,
            "crit": 1,
            "desc": "curl/wget in shell command position",
            "from": [
              {
                "file": 22
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/chmod/executable/mode::chmod-make-executable",
            "atk": "T1222",
            "mbc": "E1222",
            "conf": 0.85,
            "crit": 3,
            "desc": "chmod adds executable permissions",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "metadata/build/ci/step::mutable-version-action-ref",
            "conf": 0.9,
            "crit": 3,
            "desc": "Workflow action uses mutable version tag"
          },
          {
            "id": "metadata/package/testing/scripted::go-fuzz-corpus-entry-basename",
            "conf": 0.96,
            "crit": 3,
            "desc": "Go fuzz corpus entry basename (sha1[-index])"
          },
          {
            "id": "metadata/build/ci/step::composite-action-step-script",
            "conf": 1.0,
            "crit": 3,
            "desc": "Composite action step script body",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/file/string/identity::multi-architecture-name-set--arm-mips",
            "conf": 0.9,
            "crit": 1,
            "desc": "ARM or MIPS architecture reference",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl-output-file-command",
            "atk": "T1105",
            "conf": 0.94,
            "crit": 3,
            "desc": "Executes curl with output-path option",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::source-curl-output-option",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "curl output file source",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/release::forge-release-download-url",
            "conf": 0.95,
            "crit": 3,
            "desc": "References a release download URL path",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::fetch-output-to-var",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "Output path comes from shell variable",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::fetch-redirect-to-literal",
            "atk": "T1105",
            "conf": 0.95,
            "crit": 3,
            "desc": "Fetch redirects to a literal filename",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::fetch-var-input-before-output",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "Variable input precedes variable output",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::fetch-var-output-before-input",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "Variable output precedes variable input",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/chmod/executable/mode::chmod-plus-x-quoted-path",
            "atk": "T1222",
            "mbc": "E1222",
            "conf": 0.88,
            "crit": 3,
            "desc": "chmod plus-x on a quoted path",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/delete/file/command::rm-local-payload-file",
            "atk": "T1070.004",
            "mbc": "C0047",
            "conf": 0.88,
            "crit": 3,
            "desc": "Removes a locally named file",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/link/symlink::shell-ln-symlink",
            "conf": 0.88,
            "crit": 3,
            "desc": "Shell creates a symbolic link",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/write/file/redirect::shell-echo-file-write",
            "conf": 0.86,
            "crit": 3,
            "desc": "Shell echo redirects output to file",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/env/cicd::github-path-file",
            "conf": 0.85,
            "crit": 3,
            "desc": "GITHUB_PATH environment file",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/arch::arch-arm64",
            "conf": 1.0,
            "crit": 3,
            "desc": "arm64 architecture string",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/arch::multiple-architecture-references--x86-or-amd64",
            "conf": 0.94,
            "crit": 3,
            "desc": "x86 or AMD64 architecture reference",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/arch::multiple-architecture-references--x86-or-arm",
            "conf": 0.94,
            "crit": 1,
            "desc": "x86 or ARM architecture reference",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/string::multi-arch-runtime-wordlist--arc-or-arm",
            "atk": "T1082",
            "mbc": "E1082",
            "conf": 0.85,
            "crit": 3,
            "desc": "Shell ARC or ARM architecture selector",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/process/create/shell/build::native-toolchain-install-command",
            "atk": "T1027.004",
            "conf": 0.8,
            "crit": 1,
            "desc": "Go/Cargo install command",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::fetch-output-option-script",
            "conf": 0.85,
            "crit": 3,
            "desc": "curl/wget text includes output option",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl-output-file",
            "atk": "T1105",
            "conf": 0.7,
            "crit": 3,
            "desc": "References curl file-output option",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/curl::curl-output-staging-path",
            "atk": "T1105",
            "conf": 0.82,
            "crit": 3,
            "desc": "References curl writing to an output path",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/crypto/certificate/usage::certificate-ref",
            "conf": 0.5,
            "crit": 2,
            "desc": "References certificate terminology",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/data/archive/extract/tar::tar-extract",
            "atk": "T1560.001",
            "conf": 0.78,
            "crit": 3,
            "desc": "tar extraction command usage",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/data/archive/extract/tar::tar-gzip-extract",
            "atk": "T1560.001",
            "conf": 0.84,
            "crit": 3,
            "desc": "tar gzip extraction command usage",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/data/string/assembly::sh-template-opening-delimiter",
            "conf": 0.85,
            "crit": 3,
            "desc": "Shell contains a template delimiter",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/chmod/executable/mode::shell-plus-x",
            "atk": "T1222",
            "mbc": "E1222",
            "conf": 0.75,
            "crit": 3,
            "desc": "chmod +x (make executable)",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/chmod/modify::chmod-command",
            "atk": "T1222",
            "mbc": "E1222",
            "conf": 0.6,
            "crit": 3,
            "desc": "chmod shell command",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/directory/mkdir::mkdir-command",
            "conf": 0.8,
            "crit": 3,
            "desc": "Shell invokes mkdir command",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/process/create/shell/spawn::command-substitution",
            "conf": 1.0,
            "crit": 2,
            "desc": "shell script command substitution",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/write/file/redirect::shell-file-write-command",
            "conf": 0.86,
            "crit": 3,
            "desc": "Shell command redirects output to file",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              }
            ],
            "uses": [
              58
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::public-forge-http-download",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "Fetches content from a public code forge",
            "from": [
              {
                "file": 2
              }
            ],
            "uses": [
              10,
              37
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/cli::fetch-output-flag-script",
            "conf": 0.85,
            "crit": 3,
            "desc": "Script sets curl or wget output file",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              },
              {
                "file": 1732
              }
            ],
            "uses": [
              42,
              65
            ]
          },
          {
            "id": "micro-behaviors/communications/http/download/shell::fetch-var-output-var",
            "atk": "T1105",
            "conf": 0.9,
            "crit": 3,
            "desc": "curl/wget uses variable input and output paths",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              },
              {
                "file": 1732
              }
            ],
            "uses": [
              38,
              51
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/arch::multiple-architecture-references",
            "conf": 0.94,
            "crit": 3,
            "desc": "References multiple CPU architecture names",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              }
            ],
            "uses": [
              61,
              62
            ]
          },
          {
            "id": "micro-behaviors/os/sysinfo/platform/arch::multi-arch-target",
            "conf": 0.85,
            "crit": 3,
            "desc": "Script references multiple CPU architectures",
            "from": [
              {
                "file": 1711
              },
              {
                "file": 1712
              },
              {
                "file": 1716
              },
              {
                "file": 1717
              },
              {
                "file": 1719
              },
              {
                "file": 1720
              }
            ],
            "uses": [
              60,
              80
            ]
          },
          {
            "id": "micro-behaviors/fs/write/file/full::out-file",
            "conf": 0.9,
            "crit": 3,
            "desc": "Calls PowerShell Out-File",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "objectives/credential-access/env/secrets/bulk-access::vcs-registry-secret-env-name",
            "atk": "T1552.001",
            "mbc": "B0028",
            "conf": 0.9,
            "crit": 3,
            "desc": "VCS and registry secret names",
            "from": [
              {
                "file": 20
              }
            ]
          },
          {
            "id": "micro-behaviors/fs/path/location::home-hidden-dotdir-ref",
            "conf": 0.6,
            "crit": 3,
            "desc": "Home-relative hidden directory path literal",
            "from": [
              {
                "file": 20
              }
            ]
          }
        ]
      }
    ]
  }
}