For findings from the MCP analyzers, the JSON output has pattern: null, finding: null and code_snippet: null, and it does not serialize message. The terminal and SARIF output do show the message, e.g. MCP server referenced without pinned version: 'npx @modelcontextprotocol/server-filesystem'. So in JSON, the only thing identifying what triggered RP1 is the generic explanation.
Repro: a SKILL.md containing npx @modelcontextprotocol/server-filesystem /tmp in a bash block, scanned with --format json. Both RP1 issues have pattern and finding null.
Looks like the MCP analyzers build Finding with message and matched_text but not pattern/finding, and RP1/LP3 have no entry in PATTERN_NAMES. Possibly related to #304, which reports null finding on the LLM path.
For findings from the MCP analyzers, the JSON output has
pattern: null,finding: nullandcode_snippet: null, and it does not serializemessage. The terminal and SARIF output do show the message, e.g.MCP server referenced without pinned version: 'npx @modelcontextprotocol/server-filesystem'. So in JSON, the only thing identifying what triggered RP1 is the genericexplanation.Repro: a SKILL.md containing
npx @modelcontextprotocol/server-filesystem /tmpin a bash block, scanned with--format json. Both RP1 issues havepatternandfindingnull.Looks like the MCP analyzers build
Findingwithmessageandmatched_textbut notpattern/finding, andRP1/LP3have no entry inPATTERN_NAMES. Possibly related to #304, which reports nullfindingon the LLM path.