{"data":{"skill":{"slug":"aaron-he-zhu-content-quality-auditor","name":"content-quality-auditor","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/optimize/content-quality-auditor","status":"approved","author":"aaron-he-zhu","authorVersion":"17.0.0","skillstoreRevision":1},"audit":{"id":"246a0ed7-d715-446e-bde5-e53002525a2e","skill_id":"86761e2b-ba84-4029-9478-ab0fe632c734","version":5,"content_hash":"v3:d71c7417a35d5c2624161bd2fe8de8a41a362128:e5a4c2346e4707b545143f6198d71f2131f2138c7cf058f7ae1fc29f4a2e3310:6c808d24bd79c13100ffc43f2a2e01efe4a0c25f49885b4401c46fb2b5b2b7ef:736b696c6c732f6161726f6e2d68652d7a68752f636f6e74656e742d7175616c6974792d61756469746f72:8f70972c3ca727747febc69e3abdf024","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 51 static detections are contextual false positives from Markdown formatting, fixed documentation links, repository metadata, and scoped local tooling. No prompt injection, arbitrary path access, user-controlled command construction, network exfiltration, or other malicious intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/item-reference.md","line_end":3,"line_start":3},{"file":"references/recursive-refinement.md","line_end":14,"line_start":14},{"file":"references/recursive-refinement.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":161,"line_start":161},{"file":"SKILL.md","line_end":162,"line_start":162},{"file":"SKILL.md","line_end":165,"line_start":165},{"file":"SKILL.md","line_end":169,"line_start":169},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":171,"line_start":171},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":52,"line_start":52}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":33,"line_start":30},{"file":"SKILL.md","line_end":37,"line_start":33},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":48,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":48},{"file":"SKILL.md","line_end":50,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":84,"line_start":83},{"file":"SKILL.md","line_end":85,"line_start":84},{"file":"SKILL.md","line_end":86,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":104,"line_start":98},{"file":"SKILL.md","line_end":114,"line_start":104},{"file":"SKILL.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":115,"line_start":115},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":117,"line_start":117},{"file":"SKILL.md","line_end":119,"line_start":119},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":126,"line_start":125},{"file":"SKILL.md","line_end":137,"line_start":126},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":143,"line_start":141},{"file":"SKILL.md","line_end":145,"line_start":143},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":52,"line_start":52}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":15,"line_start":15}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":730,"audit_model":"codex","audited_at":"2026-07-12T11:35:11.03+00:00","created_at":"2026-07-14T15:53:58.536779+00:00","static_findings":[{"id":"blocker:references/auditor-runtime.md:138:system-reconnaissance","file":"references/auditor-runtime.md","pattern":"System reconnaissance","snippet":"\"condition\": \"a material connection, paid placement, or affiliate relationship exists\",","category":"blocker","line_end":138,"severity":"low","line_start":138},{"id":"filesystem:references/item-reference.md:3:path-traversal-sequence","file":"references/item-reference.md","pattern":"Path traversal sequence","snippet":"Quick reference for all 80 CORE-EEAT audit items. Full scoring criteria in [core-eeat-benchmark.md](","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/recursive-refinement.md:14:path-traversal-sequence","file":"references/recursive-refinement.md","pattern":"Path traversal sequence","snippet":"[auditor-runbook.md §4](../../../../references/auditor-runbook.md) for cap and","category":"filesystem","line_end":14,"severity":"high","line_start":14},{"id":"filesystem:references/recursive-refinement.md:45:path-traversal-sequence","file":"references/recursive-refinement.md","pattern":"Path traversal sequence","snippet":"[core-eeat-benchmark.md](../../../../references/core-eeat-benchmark.md).","category":"filesystem","line_end":45,"severity":"high","line_start":45},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":33,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":37,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use this skill for the content artifact and its source-credibility evidence. Use `on-page-seo-audito","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `../../../references/auditor-runbook.md`","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `../../../references/scoring-semantics.md`","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `../../../references/core-eeat-benchmark.md`","category":"external_commands","line_end":50,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `../../../references/framework-catalog.json` (`CORE-EEAT` entry)","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For a standalone installation, read the bundled immutable `references/auditor-runtime.md` instead. N","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Profile/content type**: `product-review`, `how-to-guide`, `comparison`, `landing-page`, `blog-po","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Use `unknown` for applicable but unobserved evidence. Use `na` only for catalog-declared conditio","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CORE-EEAT-C01`: material title/promise mismatch.","category":"external_commands","line_end":84,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CORE-EEAT-R10`: material internal factual contradiction; an isolated broken link is not this veto","category":"external_commands","line_end":85,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CORE-EEAT-T04`: a material connection exists and required disclosure is absent/materially obscure","category":"external_commands","line_end":86,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. Create a JSON run conforming to `audit-run.schema.json` and execute `python3 \"$AARON_SKILLS_ROOT/","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":104,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":114,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete, no veto, healthy score/no failures: `DONE` + `SHIP`.","category":"external_commands","line_end":114,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete, remediation needed or one veto: `DONE_WITH_CONCERNS` + `FIX`; one veto caps final at 59.","category":"external_commands","line_end":115,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete, 2+ vetoes: `DONE` + `BLOCK`; omit final score.","category":"external_commands","line_end":116,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Applicable evidence missing: `NEEDS_INPUT` + `UNDECIDED`; omit raw/final scores.","category":"external_commands","line_end":117,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Route claim/disclosure fixes to `offer-claims-registry`, content fixes to `content-writer` or `geo-c","category":"external_commands","line_end":119,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Product-review profile, complete evidence, raw 78, one verified T04 failure: `DONE_WITH_CONCERNS/F","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete evidence, verified C01 and R10 failures: `DONE/BLOCK`, raw retained, no final score.","category":"external_commands","line_end":126,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Any applicable Unknown item: `NEEDS_INPUT/UNDECIDED`, no raw or final score, regardless of the obs","category":"external_commands","line_end":137,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Default to plain-language findings. When traceability is requested, qualify IDs as `CORE-EEAT-C01`, ","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Do not write memory merely because an audit was requested. If the user explicitly authorizes persist","category":"external_commands","line_end":143,"severity":"medium","line_start":141},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":145,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:52:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"For a standalone installation, read the bundled immutable `references/auditor-runtime.md` instead. N","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:52:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"For a standalone installation, read the bundled immutable `references/auditor-runtime.md` instead. N","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:15:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"17.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"optimiz","category":"network","line_end":15,"severity":"low","line_start":15},{"id":"filesystem:SKILL.md:47:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. `../../../references/auditor-runbook.md`","category":"filesystem","line_end":47,"severity":"high","line_start":47},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"2. `../../../references/scoring-semantics.md`","category":"filesystem","line_end":48,"severity":"high","line_start":48},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"3. `../../../references/core-eeat-benchmark.md`","category":"filesystem","line_end":49,"severity":"high","line_start":49},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. `../../../references/framework-catalog.json` (`CORE-EEAT` entry)","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"For a standalone installation, read the bundled immutable `references/auditor-runtime.md` instead. N","category":"filesystem","line_end":52,"severity":"high","line_start":52},{"id":"filesystem:SKILL.md:160:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CORE-EEAT benchmark](../../../references/core-eeat-benchmark.md)","category":"filesystem","line_end":160,"severity":"high","line_start":160},{"id":"filesystem:SKILL.md:161:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Auditor runbook](../../../references/auditor-runbook.md)","category":"filesystem","line_end":161,"severity":"high","line_start":161},{"id":"filesystem:SKILL.md:162:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Scoring semantics](../../../references/scoring-semantics.md)","category":"filesystem","line_end":162,"severity":"high","line_start":162},{"id":"filesystem:SKILL.md:165:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Humanizer controls](../../../references/humanizer-slop.md)","category":"filesystem","line_end":165,"severity":"high","line_start":165},{"id":"filesystem:SKILL.md:169:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **FIX content:** [content-writer](../../build/content-writer/SKILL.md)","category":"filesystem","line_end":169,"severity":"high","line_start":169},{"id":"filesystem:SKILL.md:170:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **FIX technical evidence:** [technical-seo-checker](../../optimize/technical-seo-checker/SKILL.md)","category":"filesystem","line_end":170,"severity":"high","line_start":170},{"id":"filesystem:SKILL.md:171:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Resolve claims:** [offer-claims-registry](../../../protocol/offer-claims-registry/SKILL.md)","category":"filesystem","line_end":171,"severity":"high","line_start":171},{"id":"filesystem:SKILL.md:172:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Add domain context:** [domain-authority-auditor](../../monitor/domain-authority-auditor/SKILL.md","category":"filesystem","line_end":172,"severity":"high","line_start":172},{"id":"filesystem:SKILL.md:52:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"For a standalone installation, read the bundled immutable `references/auditor-runtime.md` instead. N","category":"filesystem","line_end":52,"severity":"low","line_start":52},{"id":"blocker:SKILL.md:39:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Reads:** one artifact plus its cited/source controls. **Writes:** only a permissioned v3 artifact.","category":"blocker","line_end":39,"severity":"low","line_start":39},{"id":"blocker:SKILL.md:152:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- All expected IDs observed, Unknown, or valid N/A; no missingness renormalization.","category":"blocker","line_end":152,"severity":"low","line_start":152}],"finding_verdicts":[{"id":"blocker:references/auditor-runtime.md:138:system-reconnaissance","reason":"This JSON condition defines when affiliate disclosure applies. It does not inspect system state, accounts, processes, or privileges.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/item-reference.md:3:path-traversal-sequence","reason":"The sequence appears in a fixed Markdown link to the documented CORE-EEAT benchmark. It does not accept user input or perform a filesystem operation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recursive-refinement.md:14:path-traversal-sequence","reason":"This is a fixed Markdown link to the auditor runbook for veto handling. It is documentation navigation, not arbitrary path access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/recursive-refinement.md:45:path-traversal-sequence","reason":"This is a fixed Markdown link to the benchmark used for dimension weights. No user-controlled path is read or written.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks start a fenced text example containing sample audit requests. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The backticks close a fenced text example. No executable expression or command is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Inline backticks format related skill names in prose. They are Markdown markup, not shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"Inline backticks format a fixed repository documentation path. No command syntax or dynamic input is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"Inline backticks format a fixed scoring-semantics path. They do not execute the path.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Inline backticks format a fixed benchmark path. The line contains no shell or Ruby invocation.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"Inline backticks identify a fixed catalog path and entry name. This is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Most backticks on this line are Markdown formatting. The command substitution runs a fixed git repository-root query without user input or data transmission.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The backticks format a closed list of supported content-type values. No executable statement is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The backticks format the literal audit states unknown and na. They are data vocabulary, not executable code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The backticks format the CORE-EEAT-C01 item identifier. The line describes a veto condition and executes nothing.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The backticks format the CORE-EEAT-R10 item identifier. This is an audit rule, not an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The backticks format the CORE-EEAT-T04 item identifier. The line only explains a disclosure condition.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The line documents a local deterministic scorer invocation with a quoted fixed root and an explicit input file. It contains no Ruby backticks, untrusted interpolation, or network action.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The backticks start a fenced Markdown output example. They do not execute a command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The backticks close a fenced Markdown output example. No executable expression is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"Inline backticks format typed status and verdict labels. They are output vocabulary, not shell syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"Inline backticks format typed status and verdict labels. The line contains no external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"Inline backticks format typed status and verdict labels for multiple vetoes. Nothing is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"Inline backticks format typed missing-evidence status labels. They are not command substitutions.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The backticks format names of related skills used for handoff. The prose does not invoke those skills or a shell.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The backticks format worked-example status values and a field name. They are illustrative audit output.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The backticks format worked-example verdict values. No command or dynamic code is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The backticks format worked-example status values. This is documentation of scoring behavior.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The backticks format qualified CORE-EEAT item identifiers. They cannot execute code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The backticks format a constrained relative artifact path. The line requires explicit permission and validation before any write.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The backticks open a fenced Bash example. The fence itself is Markdown and performs no execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:shell-command-substitution","reason":"The substitution runs a fixed git rev-parse query only to locate the repository root, suppressing errors and using no user input. It does not expose or transmit repository data.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:template-literal-with-command-substitution","reason":"This is a quoted shell variable assignment in documentation, not a JavaScript template literal. Its fixed git fallback has no user-controlled command fragment.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is repository homepage metadata. The skill does not instruct a request to this address or send data to it.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:15:hardcoded-url","reason":"The URL is repeated inside package metadata as the project homepage. It is not a network endpoint used by the audit workflow.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:47:path-traversal-sequence","reason":"This fixed path identifies the repository auditor runbook required by the skill. It is not derived from user input and does not enable arbitrary traversal.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","reason":"This fixed path identifies the repository scoring semantics document. No dynamic path construction or write occurs.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","reason":"This fixed path identifies the repository CORE-EEAT benchmark. It is a scoped documentation dependency, not arbitrary filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"This fixed path identifies the repository framework catalog and a named entry. It contains no user-controlled traversal component.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","reason":"The parent-relative segment is inside a fixed Markdown link to runtime instructions. The standalone fallback uses a bundled file and forbids searching parent directories.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:160:path-traversal-sequence","reason":"This is a fixed Markdown reference link to the CORE-EEAT benchmark. It does not read an arbitrary user-selected path.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:161:path-traversal-sequence","reason":"This is a fixed Markdown reference link to the auditor runbook. The path is documentation navigation only.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:162:path-traversal-sequence","reason":"This is a fixed Markdown reference link to scoring semantics. It has no dynamic or writable component.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:165:path-traversal-sequence","reason":"This is a fixed Markdown reference link to supporting humanizer controls. It does not perform path traversal at runtime.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:169:path-traversal-sequence","reason":"This fixed relative link points to a related content-writing skill for remediation handoff. It is not an instruction to access arbitrary files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:170:path-traversal-sequence","reason":"This fixed relative link points to a related technical SEO skill. No path input is accepted and no filesystem mutation occurs.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:171:path-traversal-sequence","reason":"This fixed relative link points to the claims registry skill. It is a documentation link, not user-controlled traversal.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:172:path-traversal-sequence","reason":"This fixed relative link points to the domain authority auditor. It does not expose arbitrary filesystem access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:52:standard-device-file-access","reason":"The only device path is /dev/null, used to suppress errors from a fixed git root query. It neither reads sensitive device data nor writes a persistent file.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:39:system-reconnaissance","reason":"This line documents the skill's read and permissioned-write scope plus completion criteria. It performs no host, account, process, or network discovery.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:152:system-reconnaissance","reason":"This validation checkpoint checks CORE-EEAT item identifiers and missingness handling. It does not inspect the host system.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","subject_content_hash":"e5a4c2346e4707b545143f6198d71f2131f2138c7cf058f7ae1fc29f4a2e3310","subject_tree_hash":"6c808d24bd79c13100ffc43f2a2e01efe4a0c25f49885b4401c46fb2b5b2b7ef","subject_plugin_path":"skills/aaron-he-zhu/content-quality-auditor","audit_payload_hash":"8f70972c3ca727747febc69e3abdf024","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","contentHash":"e5a4c2346e4707b545143f6198d71f2131f2138c7cf058f7ae1fc29f4a2e3310","treeHash":"6c808d24bd79c13100ffc43f2a2e01efe4a0c25f49885b4401c46fb2b5b2b7ef","pluginPath":"skills/aaron-he-zhu/content-quality-auditor","auditPayloadHash":"8f70972c3ca727747febc69e3abdf024"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}