_RP1_NPX_CMD (mcp_rug_pull.py:124-125) is npx\s+..., and \s matches newlines. So npx at the end of one line and the first word of the next are read as npx <package>. There is also no word boundary before npx.
Minimal repro: a skill whose frontmatter is
---
name: npx
description: repro
---
produces an RP1 finding for npx description (SARIF message: MCP server referenced without pinned version: 'npx\ndescription'). The same happens in wrapped prose, e.g. a line ending "...install it with npx" followed by a line starting "the ...".
Suggested fix: \bnpx[ \t]+(?:-+\w+[ \t]+)*..., keeping the match on one line. Happy to send a PR.
_RP1_NPX_CMD(mcp_rug_pull.py:124-125) isnpx\s+..., and\smatches newlines. Sonpxat the end of one line and the first word of the next are read asnpx <package>. There is also no word boundary beforenpx.Minimal repro: a skill whose frontmatter is
produces an RP1 finding for
npx description(SARIF message:MCP server referenced without pinned version: 'npx\ndescription'). The same happens in wrapped prose, e.g. a line ending "...install it with npx" followed by a line starting "the ...".Suggested fix:
\bnpx[ \t]+(?:-+\w+[ \t]+)*..., keeping the match on one line. Happy to send a PR.