{"data":{"skill":{"slug":"aaron-he-zhu-content-quality-auditor","name":"content-quality-auditor","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/optimize/content-quality-auditor","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"225663f6-970b-4736-8b17-b5c1c3e669e4","skill_id":"86761e2b-ba84-4029-9478-ab0fe632c734","version":3,"content_hash":"v2:7ed2830f0283f3a8900137d8dc893e54072206f3:82c1d5f4895046c55ade796a220fe6f61c6506552da0056ca005dfa50d5a48ea:66501a188a90b3945b3928d565fc0a1854baf409dcbab0aad05578654f946664:fec77b2f824ba561f758adbd4f6385a3","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static path traversal and backtick matches are false positives caused by Markdown links, examples, and inline field names. Real concerns remain around the rendered fetch command, mutable remote runbook fallback, and automatic memory writes. No evidence found of prompt injection text in the scanned files.","remediation":[{"issue":"Runtime execution of a local crawler command","severity":"medium","suggestion":"Replace the shell command instruction with approved host fetch tooling, or require explicit user confirmation plus URL scheme and private-address validation before running it."},{"issue":"Mutable remote fallback for authoritative instructions","severity":"high","suggestion":"Bundle the required runbook and references inside the skill, or pin remote fallback URLs to an immutable commit and treat fetched text as untrusted data."},{"issue":"Automatic writes to project memory files","severity":"medium","suggestion":"Ask for user confirmation before saving audit artifacts or promoting findings to persistent memory files, especially in shared repositories."},{"issue":"Parent-directory reference dependencies","severity":"low","suggestion":"Prefer local bundled reference files so standalone installs do not need to read outside the skill directory."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/item-reference.md","line_end":3,"line_start":3},{"file":"references/recursive-refinement.md","line_end":14,"line_start":14},{"file":"references/recursive-refinement.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":192,"line_start":192},{"file":"SKILL.md","line_end":199,"line_start":199},{"file":"SKILL.md","line_end":204,"line_start":204},{"file":"SKILL.md","line_end":212,"line_start":212},{"file":"SKILL.md","line_end":378,"line_start":378},{"file":"SKILL.md","line_end":429,"line_start":429},{"file":"SKILL.md","line_end":437,"line_start":437},{"file":"SKILL.md","line_end":471,"line_start":471},{"file":"SKILL.md","line_end":475,"line_start":475},{"file":"SKILL.md","line_end":478,"line_start":478},{"file":"SKILL.md","line_end":479,"line_start":479},{"file":"SKILL.md","line_end":480,"line_start":480},{"file":"SKILL.md","line_end":484,"line_start":484}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":57,"line_start":55},{"file":"SKILL.md","line_end":59,"line_start":57},{"file":"SKILL.md","line_end":61,"line_start":59},{"file":"SKILL.md","line_end":65,"line_start":61},{"file":"SKILL.md","line_end":67,"line_start":65},{"file":"SKILL.md","line_end":69,"line_start":67},{"file":"SKILL.md","line_end":71,"line_start":69},{"file":"SKILL.md","line_end":75,"line_start":71},{"file":"SKILL.md","line_end":77,"line_start":75},{"file":"SKILL.md","line_end":83,"line_start":77},{"file":"SKILL.md","line_end":86,"line_start":83},{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":98,"line_start":89},{"file":"SKILL.md","line_end":131,"line_start":98},{"file":"SKILL.md","line_end":145,"line_start":131},{"file":"SKILL.md","line_end":158,"line_start":145},{"file":"SKILL.md","line_end":169,"line_start":158},{"file":"SKILL.md","line_end":175,"line_start":169},{"file":"SKILL.md","line_end":184,"line_start":175},{"file":"SKILL.md","line_end":192,"line_start":184},{"file":"SKILL.md","line_end":199,"line_start":192},{"file":"SKILL.md","line_end":199,"line_start":199},{"file":"SKILL.md","line_end":204,"line_start":204},{"file":"SKILL.md","line_end":205,"line_start":205},{"file":"SKILL.md","line_end":206,"line_start":206},{"file":"SKILL.md","line_end":217,"line_start":210},{"file":"SKILL.md","line_end":233,"line_start":217},{"file":"SKILL.md","line_end":237,"line_start":233},{"file":"SKILL.md","line_end":253,"line_start":237},{"file":"SKILL.md","line_end":260,"line_start":253},{"file":"SKILL.md","line_end":277,"line_start":260},{"file":"SKILL.md","line_end":286,"line_start":277},{"file":"SKILL.md","line_end":294,"line_start":286},{"file":"SKILL.md","line_end":294,"line_start":294},{"file":"SKILL.md","line_end":378,"line_start":311},{"file":"SKILL.md","line_end":378,"line_start":378},{"file":"SKILL.md","line_end":389,"line_start":380},{"file":"SKILL.md","line_end":421,"line_start":389},{"file":"SKILL.md","line_end":422,"line_start":421},{"file":"SKILL.md","line_end":423,"line_start":422},{"file":"SKILL.md","line_end":424,"line_start":423},{"file":"SKILL.md","line_end":425,"line_start":424},{"file":"SKILL.md","line_end":431,"line_start":425},{"file":"SKILL.md","line_end":432,"line_start":431},{"file":"SKILL.md","line_end":432,"line_start":432},{"file":"SKILL.md","line_end":437,"line_start":437}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":199,"line_start":199}]}],"critical_findings":[],"high_findings":[{"title":"Mutable Remote Runbook Loaded as Instructions","locations":[{"file":"SKILL.md","line_end":199,"line_start":192}],"confidence":0.88,"description":"The skill makes an external runbook authoritative and tells the agent to fetch it from the raw GitHub main branch when local files are missing. This can load unreviewed future instructions into the audit flow.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The text explicitly says not to score without the runbook and provides a mutable remote fallback URL. The risk depends on installation mode, but the supply-chain path is clear."}],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":131,"line_start":98}],"confidence":0.82,"description":"**Zero-dependency rendered fetch (keyless)**: with no crawler connected, `python3 \"${CLAUDE_PLUGIN_R","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Line 98 instructs the agent to run a local python3 connector against a URL, which is real external command execution. The URL is supposed to be authorized, but the command still creates process-execution and URL-fetch risk."},{"title":"Fetch API call","locations":[{"file":"SKILL.md","line_end":98,"line_start":98}],"confidence":0.8,"description":"**Zero-dependency rendered fetch (keyless)**: with no crawler connected, `python3 \"${CLAUDE_PLUGIN_R","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"Line 98 describes fetching rendered page content from user-provided URLs through a connector. The authorization and robots.txt language lowers risk, but this remains real network retrieval behavior."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":199,"line_start":199}],"confidence":0.86,"description":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"Line 199 tells the agent to fetch runbook files from a raw GitHub main-branch URL when local references are missing. That can import mutable, unscanned instructions at runtime."},{"title":"Automatic Project Memory Writes Without User Confirmation","locations":[{"file":"SKILL.md","line_end":87,"line_start":83},{"file":"SKILL.md","line_end":437,"line_start":435}],"confidence":0.84,"description":"The skill directs the agent to save audit artifacts and promote findings into memory files, including hot-cache and open-loops, without asking the user first. This creates persistent project-state changes from a marketplace skill.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The write and promotion behavior is directly stated in the skill contract and save-results section. The paths are constrained, so this is a persistence risk rather than arbitrary file write."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":661,"audit_model":"codex","audited_at":"2026-07-07T06:04:12.197+00:00","created_at":"2026-07-07T08:33:07.129929+00:00","static_findings":[{"id":"filesystem:references/item-reference.md:3:path-traversal-sequence","file":"references/item-reference.md","pattern":"Path traversal sequence","snippet":"Quick reference for all 80 CORE-EEAT audit items. Full scoring criteria in [core-eeat-benchmark.md](","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/recursive-refinement.md:14:path-traversal-sequence","file":"references/recursive-refinement.md","pattern":"Path traversal sequence","snippet":"[auditor-runbook.md §2](../../../../references/auditor-runbook.md) for cap and","category":"filesystem","line_end":14,"severity":"high","line_start":14},{"id":"filesystem:references/recursive-refinement.md:45:path-traversal-sequence","file":"references/recursive-refinement.md","pattern":"Path traversal sequence","snippet":"[core-eeat-benchmark.md](../../../../references/core-eeat-benchmark.md).","category":"filesystem","line_end":45,"severity":"high","line_start":45},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":57,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":59,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":61,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":67,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":69,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":75,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":77,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":83,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: a CORE-EEAT audit report, a publish-readiness verdict, and a short handoff summ","category":"external_commands","line_end":86,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing audit report plus a reusable summary that can be stored under `memory/au","category":"external_commands","line_end":87,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: veto items and publish blockers to `memory/hot-cache.md` (auto-saved, no user confir","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Done when**: all 80 CORE-EEAT items are scored or marked N/A, a SHIP/FIX/BLOCK verdict is stated","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Primary next skill**: use the `Next Best Skill` below once the verdict is clear.","category":"external_commands","line_end":98,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency rendered fetch (keyless)**: with no crawler connected, `python3 \"${CLAUDE_PLUGIN_R","category":"external_commands","line_end":131,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":145,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":158,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":169,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":175,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":184,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":192,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Before scoring, `Read ../../../references/auditor-runbook.md`.** It is the authoritative, framewor","category":"external_commands","line_end":199,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","category":"external_commands","line_end":199,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[references/auditor-runbook.md §1](../../../references/auditor-runbook.md): `status`, `objective`, `","category":"external_commands","line_end":204,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`key_findings`, `evidence_summary`, `recommended_next_skill`, plus the auditor fields `cap_applied`,","category":"external_commands","line_end":205,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`raw_overall_score` (content-type weighted, floor-rounded, before cap), and `final_overall_score`.","category":"external_commands","line_end":206,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Walk the runbook's §2 decision table, then mirror the matching example below. `raw_overall_score`","category":"external_commands","line_end":217,"severity":"medium","line_start":210},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":233,"severity":"medium","line_start":217},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":237,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":253,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":260,"severity":"medium","line_start":253},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":277,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":286,"severity":"medium","line_start":277},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Year marker in title/body | Year is within `[current_year − 2, current_year]` | \"2026\" in 2026: fr","category":"external_commands","line_end":294,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"state the exception in the finding's `evidence` field. Evaluate `current_year` dynamically at audit ","category":"external_commands","line_end":294,"severity":"medium","line_start":294},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":378,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Render BEFORE \"Top 5 Priority Improvements\". Group, sort, and translate every `key_findings` entry p","category":"external_commands","line_end":378,"severity":"medium","line_start":378},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":389,"severity":"medium","line_start":380},{"id":"external_commands:SKILL.md:389:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":421,"severity":"medium","line_start":389},{"id":"external_commands:SKILL.md:421:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For full content rewrite: use `content-writer` with CORE-EEAT constraints","category":"external_commands","line_end":422,"severity":"medium","line_start":421},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For GEO optimization: use `geo-content-optimizer` targeting failed GEO-First items","category":"external_commands","line_end":423,"severity":"medium","line_start":422},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For content refresh: use `content-writer` with weak dimensions as focus","category":"external_commands","line_end":424,"severity":"medium","line_start":423},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For technical fixes: run `/aaron-marketing:seo-geo --mode audit --tech` for site-level issues","category":"external_commands","line_end":425,"severity":"medium","line_start":424},{"id":"external_commands:SKILL.md:425:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":431,"severity":"medium","line_start":425},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Cap Enforcement** (Runbook §2): walk the decision table. Identify which scenario matches your i","category":"external_commands","line_end":432,"severity":"medium","line_start":431},{"id":"external_commands:SKILL.md:432:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Artifact Gate Self-Check** (Runbook §4): run the 7-item checklist. If any item fails, force `st","category":"external_commands","line_end":432,"severity":"medium","line_start":432},{"id":"external_commands:SKILL.md:437:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Write the audit artifact to `memory/audits/content/YYYY-MM-DD-<topic>.md` (the per-role path from [s","category":"external_commands","line_end":437,"severity":"medium","line_start":437},{"id":"network:SKILL.md:98:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"**Zero-dependency rendered fetch (keyless)**: with no crawler connected, `python3 \"${CLAUDE_PLUGIN_R","category":"network","line_end":98,"severity":"low","line_start":98},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:15:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.1\", \"discipline\": \"seo-geo\", \"phase\": \"optimiz","category":"network","line_end":15,"severity":"low","line_start":15},{"id":"network:SKILL.md:20:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> Based on [CORE-EEAT Content Benchmark](https://github.com/aaron-he-zhu/core-eeat-content-benchmark","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:SKILL.md:199:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","category":"network","line_end":199,"severity":"low","line_start":199},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Based on [CORE-EEAT Content Benchmark](https://github.com/aaron-he-zhu/core-eeat-content-benchmark","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:SKILL.md:51:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Start with one of these prompts. Finish with a publish verdict and a handoff summary using the repos","category":"filesystem","line_end":51,"severity":"high","line_start":51},{"id":"filesystem:SKILL.md:93:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> See [CONNECTORS.md](../../../CONNECTORS.md) for tool category placeholders.","category":"filesystem","line_end":93,"severity":"high","line_start":93},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Fetch only user-provided or authorized URLs after [SECURITY.md §Scraping Boundaries](../../../SECURI","category":"filesystem","line_end":96,"severity":"high","line_start":96},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Evaluate each item against the criteria in [references/core-eeat-benchmark.md](../../../references/c","category":"filesystem","line_end":151,"severity":"high","line_start":151},{"id":"filesystem:SKILL.md:192:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Before scoring, `Read ../../../references/auditor-runbook.md`.** It is the authoritative, framewor","category":"filesystem","line_end":192,"severity":"high","line_start":192},{"id":"filesystem:SKILL.md:199:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","category":"filesystem","line_end":199,"severity":"high","line_start":199},{"id":"filesystem:SKILL.md:204:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[references/auditor-runbook.md §1](../../../references/auditor-runbook.md): `status`, `objective`, `","category":"filesystem","line_end":204,"severity":"high","line_start":204},{"id":"filesystem:SKILL.md:212:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> [core-eeat-benchmark.md §Content-Type Weight Table](../../../references/core-eeat-benchmark.md)),","category":"filesystem","line_end":212,"severity":"high","line_start":212},{"id":"filesystem:SKILL.md:378:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Render BEFORE \"Top 5 Priority Improvements\". Group, sort, and translate every `key_findings` entry p","category":"filesystem","line_end":378,"severity":"high","line_start":378},{"id":"filesystem:SKILL.md:429:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Execute in order, using the framework-agnostic procedure in [references/auditor-runbook.md](../../..","category":"filesystem","line_end":429,"severity":"high","line_start":429},{"id":"filesystem:SKILL.md:437:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Write the audit artifact to `memory/audits/content/YYYY-MM-DD-<topic>.md` (the per-role path from [s","category":"filesystem","line_end":437,"severity":"high","line_start":437},{"id":"filesystem:SKILL.md:471:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"7. **Pair with CITE for domain-level context** — A high content score on a low-authority domain sign","category":"filesystem","line_end":471,"severity":"high","line_start":471},{"id":"filesystem:SKILL.md:475:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CORE-EEAT Content Benchmark](../../../references/core-eeat-benchmark.md) — Full 80-item benchmark","category":"filesystem","line_end":475,"severity":"high","line_start":475},{"id":"filesystem:SKILL.md:478:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Humanizer Slop List](../../../references/humanizer-slop.md) — **SOFT penalty (NON-veto)** mapped ","category":"filesystem","line_end":478,"severity":"high","line_start":478},{"id":"filesystem:SKILL.md:479:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Visual Quality Rubric](../../../references/scoring-rubrics/visual-quality.md) — Advisory rubric f","category":"filesystem","line_end":479,"severity":"high","line_start":479},{"id":"filesystem:SKILL.md:480:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [AI Citation Patterns](../../build/geo-content-optimizer/references/ai-citation-patterns.md) — Ref","category":"filesystem","line_end":480,"severity":"high","line_start":480},{"id":"filesystem:SKILL.md:484:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"FIX: [content-writer](../../build/content-writer/SKILL.md). BLOCK: [entity-optimizer](../../../proto","category":"filesystem","line_end":484,"severity":"high","line_start":484}],"finding_verdicts":[{"id":"filesystem:references/item-reference.md:3:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:references/recursive-refinement.md:14:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:references/recursive-refinement.md:45:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"Line 98 instructs the agent to run a local python3 connector against a URL, which is real external command execution. The URL is supposed to be authorized, but the command still creates process-execution and URL-fetch risk.","verdict":"confirmed","severity":"medium","confidence":0.82},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The scanner matched Markdown inline code formatting, not executable Ruby or shell backticks. No command substitution behavior is present at this location.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"The backticked terms on this line are installation-path examples, not an instruction to execute shell backticks. Network behavior on the same line is adjudicated separately.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:217:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:253:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:389:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:421:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:423:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:425:ruby-shell-backtick-execution","reason":"The backticks are Markdown fences or prompt examples, not Ruby or shell execution syntax. The text is illustrative output format, not executable code.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:431:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:432:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:437:ruby-shell-backtick-execution","reason":"The backticked text names fields, paths, skills, or slash-command style workflow steps in Markdown. It is not shell backtick evaluation or command substitution.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:98:fetch-api-call","reason":"Line 98 describes fetching rendered page content from user-provided URLs through a connector. The authorization and robots.txt language lowers risk, but this remains real network retrieval behavior.","verdict":"confirmed","severity":"medium","confidence":0.8},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is homepage metadata in the skill frontmatter. It is not used for runtime fetching or data transfer.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:15:hardcoded-url","reason":"The URL is homepage metadata in the skill frontmatter. It is not used for runtime fetching or data transfer.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:20:hardcoded-url","reason":"The URL is a citation to the public CORE-EEAT benchmark. It is documentation context, not a runtime network request.","verdict":"false_positive","confidence":0.9},{"id":"network:SKILL.md:199:hardcoded-url","reason":"Line 199 tells the agent to fetch runbook files from a raw GitHub main-branch URL when local references are missing. That can import mutable, unscanned instructions at runtime.","verdict":"confirmed","severity":"medium","confidence":0.86},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:51:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:93:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:192:path-traversal-sequence","reason":"This is a fixed instruction to read a repository reference file, not a user-controlled path. It may be a packaging concern, but the static path traversal pattern is not an exploit by itself.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:199:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:204:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:212:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:378:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:429:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:437:path-traversal-sequence","reason":"The traversal sequence appears inside a fixed Markdown reference link while the write target is a constrained memory/audits path. There is no user-controlled filesystem path construction in the scanned text.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:471:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:475:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:478:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:479:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:480:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:484:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown documentation link to repository references or related skills. No user input is concatenated into a filesystem path.","verdict":"false_positive","confidence":0.84}],"semantic_findings":[{"title":"Mutable Remote Runbook Loaded as Instructions","severity":"high","locations":[{"file":"SKILL.md","line_end":199,"line_start":192}],"confidence":0.88,"description":"The skill makes an external runbook authoritative and tells the agent to fetch it from the raw GitHub main branch when local files are missing. This can load unreviewed future instructions into the audit flow.","confidence_reasoning":"The text explicitly says not to score without the runbook and provides a mutable remote fallback URL. The risk depends on installation mode, but the supply-chain path is clear."},{"title":"Automatic Project Memory Writes Without User Confirmation","severity":"medium","locations":[{"file":"SKILL.md","line_end":87,"line_start":83},{"file":"SKILL.md","line_end":437,"line_start":435}],"confidence":0.84,"description":"The skill directs the agent to save audit artifacts and promote findings into memory files, including hot-cache and open-loops, without asking the user first. This creates persistent project-state changes from a marketplace skill.","confidence_reasoning":"The write and promotion behavior is directly stated in the skill contract and save-results section. The paths are constrained, so this is a persistence risk rather than arbitrary file write."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}