Real catalog pins from the 2026-09-20 intake batch scored on text that cannot run on
the installing host:
1. `.github/workflows/*.yml` — a CI step's own `os.environ['RUNNER_TEMP']` read scored
`python_os_environ/high` and made a clean plugin `caution` (remarkable). A workflow
runs on the forge's runner; it now takes the README prose cap (one step down,
agent-facing shapes like `curl | sh` keep full severity).
2. "pip install" inside a user-facing message literal (`"... no pip install is needed"`,
image-utils) scored `unpinned_pip_install/medium`; mid-literal, non-command position,
no exec verb on the line → low. `"pip install x"`, `python -m pip install`, `uv pip`,
`subprocess.run("pip install …")` keep medium.
3. `desktop_surface_findings()` was being run by batch tooling over every `*.js`/`*.mjs`
in a repo and flagged a Node sidecar's lazy `import('jszip')` (remarkable). The
product check was already scoped to `desktop/`; expose that scope as
`is_desktop_surface()` / `desktop_surface_hits()` so tooling shares it.
4. `127.0.0.1:<port>` (README, .mcp.json, client defaults) scored `hardcoded_ip_port` as
network egress; a line whose every IP:port is loopback → low. A routable address on
the line keeps medium.
Every finding stays in the report. PLUGIN_SCANNER_VERSION → plugin-guard-v8 so cached
verdicts on quarantined pins are re-evaluated.