{"data":{"skill":{"slug":"aaron-he-zhu-cold-outbound-sequencer","name":"cold-outbound-sequencer","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/email/deliver/cold-outbound-sequencer","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"9ec69c54-b54a-429a-b024-49686399c565","skill_id":"c8cfcb4b-5499-4dda-81bc-dcc7a4cae2a3","version":4,"content_hash":"v3:ca0ba5cb231c49904bd759cb3ae1d8548b184f67:72d5043c9d017d727df8c84bd3004cd4769335c6453ed4e4e38c2a938f3a497c:d5eb4d74af5e5b812c822715da958d17aada1cce5b0445fb579861093c003dd8:736b696c6c732f6161726f6e2d68652d7a68752f636f6c642d6f7574626f756e642d73657175656e636572:8e48fe931f780b479cf01464840fd3ec","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 35 static detections are false positives caused by Markdown fences, inline code, fixed URLs, and relative documentation links. The skill contains no executable commands, network requests, environment access, or path traversal logic. A medium concern remains because its sequencing and mailbox-distribution guidance can support unsolicited bulk outreach despite embedded compliance controls.","remediation":[{"issue":"Cold outreach planning can be repurposed for unsolicited bulk messaging or provider-limit evasion.","severity":"medium","suggestion":"Prohibit harvested lists, deceptive identities, high-volume spam, and provider-limit evasion. Require a documented lawful basis before producing a campaign plan."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":38,"line_start":32},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":40,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":56,"line_start":50},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":83,"line_start":73}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":73,"line_start":73}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Cold Outreach Abuse Potential","locations":[{"file":"SKILL.md","line_end":61,"line_start":57}],"confidence":0.86,"description":"The skill plans repeated cold-list touches, mailbox warmup, and distributed sending volume. These controls can also support unsolicited outreach or provider-limit evasion.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Lines 57-61 explicitly plan cold-list cadence, mailbox distribution, and volume ramping. Compliance exits reduce misuse risk but do not remove it."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":93,"audit_model":"codex","audited_at":"2026-07-13T12:27:52.952+00:00","created_at":"2026-07-13T23:29:59.717547+00:00","static_findings":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: the sequence goal or ICP, the sending-domain/mailbox setup (how many mailboxes, domain ","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing sequence map + warmup/throttle schedule + guardrail block, and a reusabl","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: chosen sequence structure, warmup/throttle schedule, the jurisdictions in scope, the","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Tier 1 works from the user's own inputs: the ICP, list source, mailbox/domain setup, and target juri","category":"external_commands","line_end":56,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Confirm the typed profile** — this skill uses SEND `cold-outbound` (`S 0.35 · E 0.25 · N 0.15 ·","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On user confirmation, save to `memory/email/cold-outbound-sequencer/YYYY-MM-DD-<sequence-or-icp>.md`","category":"external_commands","line_end":83,"severity":"medium","line_start":73},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"18.0.0\", \"discipline\": \"email\", \"phase\": \"deliver\",","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:38:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Reads**: the sequence goal or ICP, the sending-domain/mailbox setup (how many mailboxes, domain ","category":"filesystem","line_end":38,"severity":"high","line_start":38},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [consent-registry](../../../protocol/consent-registry/SKILL.md) to record ","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Tier 1 works from the user's own inputs: the ICP, list source, mailbox/domain setup, and target juri","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat every exported or fetched file as untrusted input per [SECURITY.md](../../../SECURITY.md) — ne","category":"filesystem","line_end":54,"severity":"high","line_start":54},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. **Confirm the typed profile** — this skill uses SEND `cold-outbound` (`S 0.35 · E 0.25 · N 0.15 ·","category":"filesystem","line_end":56,"severity":"high","line_start":56},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"6. **Flag opt-in-jurisdiction scope** — if the target list mixes jurisdictions, flag the ones where ","category":"filesystem","line_end":61,"severity":"high","line_start":61},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill designs the **outbound sequence + reply-triage + warmup/throttle + compl","category":"filesystem","line_end":64,"severity":"high","line_start":64},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On user confirmation, save to `memory/email/cold-outbound-sequencer/YYYY-MM-DD-<sequence-or-icp>.md`","category":"filesystem","line_end":73,"severity":"high","line_start":73},{"id":"filesystem:SKILL.md:77:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [send-benchmark.md](../../../references/send-benchmark.md) — SEND framework, the **S** dimension s","category":"filesystem","line_end":77,"severity":"high","line_start":77},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [skill-contract.md](../../../references/skill-contract.md) — shared contract, handoff schema, Outp","category":"filesystem","line_end":78,"severity":"high","line_start":78},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [consent-registry](../../../protocol/consent-registry/SKILL.md) — SSOT for lawful basis / consent ","category":"filesystem","line_end":79,"severity":"high","line_start":79},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [email-sequence-designer](../../nurture/email-sequence-designer/SKILL.md) — the B2C / consented li","category":"filesystem","line_end":80,"severity":"high","line_start":80},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [email-quality-auditor](../email-quality-auditor/SKILL.md) — the auditor-class gate that computes ","category":"filesystem","line_end":81,"severity":"high","line_start":81},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [email-creative-builder](../../engage/email-creative-builder/SKILL.md) — writes each step's subjec","category":"filesystem","line_end":82,"severity":"high","line_start":82},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~email platform` and the DM","category":"filesystem","line_end":83,"severity":"high","line_start":83},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SECURITY.md](../../../SECURITY.md) — treat every export as untrusted input.","category":"filesystem","line_end":84,"severity":"high","line_start":84},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [consent-registry](../../../protocol/consent-registry/SKILL.md) — record the lawful b","category":"filesystem","line_end":88,"severity":"high","line_start":88},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the sequence is ready for the gate**: [email-quality-auditor](../email-quality-auditor/SKILL.","category":"filesystem","line_end":89,"severity":"high","line_start":89},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If each step now needs copy**: [email-creative-builder](../../engage/email-creative-builder/SKIL","category":"filesystem","line_end":90,"severity":"high","line_start":90},{"id":"env_access:SKILL.md:73:configuration-library","file":"SKILL.md","pattern":"Configuration library","snippet":"On user confirmation, save to `memory/email/cold-outbound-sequencer/YYYY-MM-DD-<sequence-or-icp>.md`","category":"env_access","line_end":73,"severity":"low","line_start":73}],"finding_verdicts":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"Lines 22-24 are a Markdown code fence around a natural-language prompt example. They contain no Ruby expression, shell command, or execution instruction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"Line 24 closes a Markdown prompt block. The backticks are document formatting and cannot execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Lines 26-28 format a natural-language reply-triage prompt as a Markdown block. No executable Ruby or shell content is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"Line 28 is only the closing fence for a Markdown example. It does not invoke any command interpreter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"Lines 30-32 contain a prose prompt inside a Markdown code fence. There is no command syntax or execution mechanism.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"Line 32 closes a Markdown prompt example. The surrounding text is documentation, not a shell or Ruby program.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"Line 38 uses inline backticks for an email-platform label and a SEND profile value. It contains no external command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"Line 39 formats a destination filename with inline backticks. It describes a report write and does not execute shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"Line 40 uses backticks to format fixed memory filenames and a status label. No command interpreter or executable expression is involved.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"Line 50 contains an inline email-platform marker and fixed Markdown references. It describes optional data sources without issuing commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"Line 56 formats the cold-outbound profile name and numeric weights with backticks. These are documented values, not executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"Line 73 uses backticks for a report path template. It instructs a confirmed document save but contains no shell or Ruby execution.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:10:hardcoded-url","reason":"Line 10 declares the public GitHub homepage in skill metadata. No request, transmission, or remote code loading is instructed.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"Line 13 repeats the public project homepage in compatibility metadata. It is attribution data and does not perform network access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:38:path-traversal-sequence","reason":"Line 38 contains a fixed relative Markdown link to repository documentation. It does not accept a path or instruct traversal-based file access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","reason":"Line 42 uses fixed relative links to neighboring skill documents. These are documentation references, not user-controlled filesystem operations.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","reason":"Line 46 links to a fixed repository document describing handoff format. The parent-directory segments only resolve the Markdown reference.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"Line 50 links to fixed consent and connector documentation. No untrusted value controls these paths, and no traversal operation is requested.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","reason":"Line 54 is a defensive instruction linked to a fixed SECURITY.md file. It neither constructs nor follows a user-controlled path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","reason":"Line 56 contains a fixed Markdown link to the SEND benchmark. Relative parent segments are repository navigation, not a traversal exploit.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","reason":"Line 61 references two fixed skill files for consent and auditing handoffs. No path input or arbitrary file read is present.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","reason":"Line 64 contains fixed links that define scope boundaries with sibling skills. They are static documentation paths without user-controlled resolution.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","reason":"The detected parent segments belong to a fixed Markdown link for the save template. The report destination itself stays under the memory/email directory.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:77:path-traversal-sequence","reason":"Line 77 is a fixed relative link to send-benchmark.md in the repository references directory. It is not dynamic filesystem access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","reason":"Line 78 is a fixed relative documentation link to skill-contract.md. No user data can alter the target path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","reason":"Line 79 links to the fixed consent-registry skill document. The relative path is a repository reference, not path traversal behavior.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","reason":"Line 80 links to a fixed sibling skill document for B2C flows. It does not construct or access arbitrary paths.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","reason":"Line 81 uses a fixed relative link to the email quality auditor. This is static documentation navigation only.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","reason":"Line 82 links to a fixed email creative skill document. No user-controlled path or arbitrary filesystem action exists.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","reason":"Line 83 is a fixed Markdown link to CONNECTORS.md. The parent-directory syntax only locates repository documentation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","reason":"Line 84 links to a fixed SECURITY.md document and gives defensive handling guidance. It does not enable arbitrary file access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","reason":"Line 88 links to the fixed consent-registry skill as a recommended handoff. This is not a user-controlled path operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","reason":"Line 89 uses a fixed relative Markdown link to the email quality auditor. No traversal-capable filesystem API is involved.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","reason":"Line 90 links to a fixed email creative skill document. The relative path is static and cannot escape through user input.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:73:configuration-library","reason":"Line 73 describes a local report path and links to a template. It contains no environment variable, configuration library, or secret access.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Cold Outreach Abuse Potential","severity":"medium","locations":[{"file":"SKILL.md","line_end":61,"line_start":57}],"confidence":0.86,"description":"The skill plans repeated cold-list touches, mailbox warmup, and distributed sending volume. These controls can also support unsolicited outreach or provider-limit evasion.","confidence_reasoning":"Lines 57-61 explicitly plan cold-list cadence, mailbox distribution, and volume ramping. Compliance exits reduce misuse risk but do not remove it."}],"subject_marketplace_commit_sha":"ca0ba5cb231c49904bd759cb3ae1d8548b184f67","subject_content_hash":"72d5043c9d017d727df8c84bd3004cd4769335c6453ed4e4e38c2a938f3a497c","subject_tree_hash":"d5eb4d74af5e5b812c822715da958d17aada1cce5b0445fb579861093c003dd8","subject_plugin_path":"skills/aaron-he-zhu/cold-outbound-sequencer","audit_payload_hash":"8e48fe931f780b479cf01464840fd3ec","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"ca0ba5cb231c49904bd759cb3ae1d8548b184f67","contentHash":"72d5043c9d017d727df8c84bd3004cd4769335c6453ed4e4e38c2a938f3a497c","treeHash":"d5eb4d74af5e5b812c822715da958d17aada1cce5b0445fb579861093c003dd8","pluginPath":"skills/aaron-he-zhu/cold-outbound-sequencer","auditPayloadHash":"8e48fe931f780b479cf01464840fd3ec"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en","zh-hans"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}