52bec9d77e
`_scan_file` matches every threat pattern against every line with no notion of what the line is. The path-token patterns — `authorized_keys`, `~/.aws`, `~/.ssh` — therefore cannot tell `cat ~/.ssh/authorized_keys` from a skill that spells the path in order to REFUSE to read it. One `critical` becomes `dangerous` in `_determine_verdict`, and on a community source that blocks the install with no `--force`, so the skill that bothered to skip credential files is the one that gets quarantined (#92478). Demote, do not drop, following the precedent `allowed_tools_field` already sets in this file: the finding keeps its file, line and matched text so an auditor still sees the token; it just stops deciding the verdict alone. Two contexts qualify, and only for the eight path-reference pattern ids: - a whole-line comment, in a language that HAS comments, drops to `low`. Markdown is deliberately excluded: `#` opens a heading there, and Markdown prose is the prompt-injection surface itself. - a line inside a construct NAMED as a denylist (`SKIP_PATTERNS`, `DENY_*`, `EXCLUDE_*`), carrying no verb that could touch the path, drops to `medium`. The issue also suggested demoting any quoted token on a verb-free line. That is wider than it looks — a fragment in quotes can be interpolated into a command a line later — so the name test is the primary rule and the verb test only guards it, because the construct's name is attacker-chosen. The denylist check is statement-aware rather than per-line: the reported match sat on a continuation line of a multi-line regex whose name is four lines up, which a per-line test reads as anonymous. 8 tests. Reverting the demotion fails the two behaviour tests and leaves the six contract tests green; dropping the verb guard, the Markdown exclusion, or the statement-awareness each fails exactly its own test. (cherry picked from commit f50acd34f62375926bd5843125e106f7e7eb6ee8)