ruzzy

skills-sh:trailofbits_skills__ruzzy

View source
A
100/100

First Seen

Feb 18, 2026

Last Scanned

Feb 20, 2026

Findings

3

Score

100/100

LOW 3

Findings (3)

LOW
Mutable GitHub raw content reference
L42

Detects references to raw.githubusercontent.com on mutable branches like main/master

github.com/trailofbits/ruzzy/blob/main/Dockerfile)
FIX

Replace GitHub raw.githubusercontent.com references with pinned commit SHAs instead of branch names (e.g., /commit-sha/file instead of /main/file). Branch references are mutable.

FP?

Likely FP if the raw GitHub URL points to a versioned release tag in a well-known repository, though even tags are technically mutable.

LOW
Cargo or gem install from remote
L60

Detects cargo install or gem install fetching packages from remote registries

gem install r
FIX

Pin Cargo/Gem packages to specific versions (e.g., cargo install tool@0.1.0, gem install tool -v 1.2.3). Use lock files for reproducibility.

FP?

Likely FP if the matched text is a very short fragment (3 words or fewer) or uses placeholder package names.

LOW
Cargo or gem install from remote
L324

Detects cargo install or gem install fetching packages from remote registries

gem install m
FIX

Pin Cargo/Gem packages to specific versions (e.g., cargo install tool@0.1.0, gem install tool -v 1.2.3). Use lock files for reproducibility.

FP?

Likely FP if the matched text is a very short fragment (3 words or fewer) or uses placeholder package names.