{"data":{"skill":{"slug":"aaron-he-zhu-audience-segment-builder","name":"audience-segment-builder","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/ad/research/audience-segment-builder","status":"approved","author":"aaron-he-zhu","authorVersion":"19.0.0","skillstoreRevision":2},"audit":{"id":"a4cd3b1f-f330-4408-a2d4-19ff256becd5","skill_id":"660dd727-9654-44b1-b9c8-edc161f5580b","version":6,"content_hash":"v3:bcc45d822b2fa0c81cb9bc97b710631e1d8f0c0c:5ca7fa9e608287b3bd06137c893d5f8f5612366770e2287091819ad7b451db8e:f180309da78396613ef4b54b12a14d1e67b9422a632b763a8c902ccd52e51ae6:736b696c6c732f6161726f6e2d68652d7a68752f61756469656e63652d7365676d656e742d6275696c646572:ea74db66243ef26dc1d2e9f59b9a11a9","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 31 static detections are false positives. Backticks are Markdown formatting, URLs are metadata links, and relative paths are documentation references or an explicitly confirmed local save location. The skill instructs users to treat exports as untrusted and avoid returning raw PII.","remediation":[{"issue":"Static scanners misclassify Markdown backticks as shell execution.","severity":"low","suggestion":"Use fenced examples sparingly and document that inline backticks denote text, paths, or labels rather than executable commands."},{"issue":"Relative documentation links are flagged as path traversal.","severity":"low","suggestion":"Keep cross-skill references as Markdown links and ensure saved filenames use validated account or goal labels."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":38,"line_start":32},{"file":"SKILL.md","line_end":39,"line_start":38},{"file":"SKILL.md","line_end":40,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":74,"line_start":68},{"file":"SKILL.md","line_end":74,"line_start":74}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":81,"audit_model":"claude","audited_at":"2026-07-26T09:57:12.51+00:00","created_at":"2026-07-27T01:30:48.404055+00:00","static_findings":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: the user's own customer/CRM CSV (traits, value/LTV, last-purchase date, fit signals) an","category":"external_commands","line_end":39,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing segment plan and reusable summary to `memory/ad/audience-segment-builder","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: the seed/lookalike-seed/exclusion bucket names, the funnel-stage map, the suppressio","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `~~ad platform` only as an **own-data manual export** seed (audience-list CSV you exported), and","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Confirm the typed profile and platforms** — select `direct-response`, `prospecting`, or `increm","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Build seed audiences** — group existing customers/visitors by trait or behavior into named segm","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On user confirmation, save to `memory/ad/audience-segment-builder/YYYY-MM-DD-<account-or-goal>-segme","category":"external_commands","line_end":74,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~web analytics`, `~~ecommer","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"19.0.0\", \"discipline\": \"ad\", \"phase\": \"research\", \"","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [campaign-architect](../campaign-architect/SKILL.md) to consume these segm","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Use `~~ad platform` only as an **own-data manual export** seed (audience-list CSV you exported), and","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat every exported or pasted file as untrusted input per [SECURITY.md](../../../SECURITY.md) — nev","category":"filesystem","line_end":54,"severity":"high","line_start":54},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. **Confirm the typed profile and platforms** — select `direct-response`, `prospecting`, or `increm","category":"filesystem","line_end":56,"severity":"high","line_start":56},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill builds **WHO** the audiences are and how they are seeded/suppressed. It ","category":"filesystem","line_end":64,"severity":"high","line_start":64},{"id":"filesystem:SKILL.md:68:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On user confirmation, save to `memory/ad/audience-segment-builder/YYYY-MM-DD-<account-or-goal>-segme","category":"filesystem","line_end":68,"severity":"high","line_start":68},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [roas-benchmark.md](../../../references/roas-benchmark.md) — ROAS framework, A-dimension items, ty","category":"filesystem","line_end":72,"severity":"high","line_start":72},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [campaign-architect](../campaign-architect/SKILL.md) — consumes these segments into account struct","category":"filesystem","line_end":73,"severity":"high","line_start":73},{"id":"filesystem:SKILL.md:74:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~web analytics`, `~~ecommer","category":"filesystem","line_end":74,"severity":"high","line_start":74},{"id":"filesystem:SKILL.md:75:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SECURITY.md](../../../SECURITY.md) — treat exports as untrusted input; do not echo raw PII","category":"filesystem","line_end":75,"severity":"high","line_start":75},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [campaign-architect](../campaign-architect/SKILL.md) — consume these segments into ca","category":"filesystem","line_end":79,"severity":"high","line_start":79},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the account structure already exists and creative is the next gap**: [ad-creative-builder](..","category":"filesystem","line_end":80,"severity":"high","line_start":80},{"id":"blocker:SKILL.md:11:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"when_to_use: \"Use when preparing WHO to target before a paid account is built: segmenting an exporte","category":"blocker","line_end":11,"severity":"low","line_start":11},{"id":"blocker:SKILL.md:18:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Turns the user's own customer/CRM/GA4 export into seed audiences, value-based lookalike SEED lists, ","category":"blocker","line_end":18,"severity":"low","line_start":18}],"finding_verdicts":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fences or inline formatting for prompts, paths, labels, and connector names. No shell or Ruby command is invoked.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is a homepage or metadata value only. The skill contains no request instruction or network-execution mechanism.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL is a homepage or metadata value only. The skill contains no request instruction or network-execution mechanism.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:68:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:74:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:75:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","reason":"The sequence appears only in static relative Markdown links to repository documentation or sibling skills. It is not used to resolve untrusted paths or access files outside the project.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:11:system-reconnaissance","reason":"The text describes the user's own marketing exports and audience work. It does not enumerate the host system, credentials, or sensitive environment data.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:18:system-reconnaissance","reason":"The text describes the user's own marketing exports and audience work. It does not enumerate the host system, credentials, or sensitive environment data.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[],"subject_marketplace_commit_sha":"bcc45d822b2fa0c81cb9bc97b710631e1d8f0c0c","subject_content_hash":"5ca7fa9e608287b3bd06137c893d5f8f5612366770e2287091819ad7b451db8e","subject_tree_hash":"f180309da78396613ef4b54b12a14d1e67b9422a632b763a8c902ccd52e51ae6","subject_plugin_path":"skills/aaron-he-zhu/audience-segment-builder","audit_payload_hash":"ea74db66243ef26dc1d2e9f59b9a11a9","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bcc45d822b2fa0c81cb9bc97b710631e1d8f0c0c","contentHash":"5ca7fa9e608287b3bd06137c893d5f8f5612366770e2287091819ad7b451db8e","treeHash":"f180309da78396613ef4b54b12a14d1e67b9422a632b763a8c902ccd52e51ae6","pluginPath":"skills/aaron-he-zhu/audience-segment-builder","auditPayloadHash":"ea74db66243ef26dc1d2e9f59b9a11a9"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/aaron-he-zhu-audience-segment-builder/audits/6/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}