{"data":{"skill":{"slug":"aaron-he-zhu-domain-authority-auditor","name":"domain-authority-auditor","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/domain-authority-auditor","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"e63a58fe-8d6d-4171-bff1-d365190ec2b3","skill_id":"67470902-f698-45c1-b1be-85a7065f4386","version":1,"content_hash":"70ddd0b5a0819a34a668c8914af9cb45","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Reviewed all 70 static findings and found the command, traversal, URL, and reconnaissance hits to be false positives caused by Markdown formatting, repository-relative links, and metadata references. No prompt injection text was found in the reviewed files. Two context-level risks remain: unpinned remote reference loading and persistent storage of audit data.","remediation":[{"issue":"Unpinned remote reference fallback","severity":"medium","suggestion":"Pin fallback reference URLs to a release tag or content hash, or require user confirmation before loading main-branch instructions."},{"issue":"Persistent audit and hot-cache writes","severity":"low","suggestion":"Ask for user consent before saving audit artifacts, and redact sensitive competitor, penalty, or private analytics data when possible."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/example-report.md","line_end":96,"line_start":92},{"file":"references/example-report.md","line_end":97,"line_start":96},{"file":"references/example-report.md","line_end":98,"line_start":97},{"file":"references/example-report.md","line_end":99,"line_start":98},{"file":"SKILL.md","line_end":58,"line_start":55},{"file":"SKILL.md","line_end":62,"line_start":58},{"file":"SKILL.md","line_end":65,"line_start":62},{"file":"SKILL.md","line_end":69,"line_start":65},{"file":"SKILL.md","line_end":71,"line_start":69},{"file":"SKILL.md","line_end":75,"line_start":71},{"file":"SKILL.md","line_end":77,"line_start":75},{"file":"SKILL.md","line_end":83,"line_start":77},{"file":"SKILL.md","line_end":86,"line_start":83},{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":131,"line_start":89},{"file":"SKILL.md","line_end":140,"line_start":131},{"file":"SKILL.md","line_end":156,"line_start":140},{"file":"SKILL.md","line_end":169,"line_start":156},{"file":"SKILL.md","line_end":189,"line_start":169},{"file":"SKILL.md","line_end":195,"line_start":189},{"file":"SKILL.md","line_end":213,"line_start":195},{"file":"SKILL.md","line_end":219,"line_start":213},{"file":"SKILL.md","line_end":226,"line_start":219},{"file":"SKILL.md","line_end":226,"line_start":226},{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":232,"line_start":232},{"file":"SKILL.md","line_end":233,"line_start":233},{"file":"SKILL.md","line_end":239,"line_start":234},{"file":"SKILL.md","line_end":245,"line_start":239},{"file":"SKILL.md","line_end":260,"line_start":245},{"file":"SKILL.md","line_end":264,"line_start":260},{"file":"SKILL.md","line_end":279,"line_start":264},{"file":"SKILL.md","line_end":285,"line_start":279},{"file":"SKILL.md","line_end":302,"line_start":285},{"file":"SKILL.md","line_end":317,"line_start":302},{"file":"SKILL.md","line_end":335,"line_start":317},{"file":"SKILL.md","line_end":371,"line_start":335},{"file":"SKILL.md","line_end":371,"line_start":371},{"file":"SKILL.md","line_end":382,"line_start":373},{"file":"SKILL.md","line_end":426,"line_start":382},{"file":"SKILL.md","line_end":427,"line_start":426},{"file":"SKILL.md","line_end":428,"line_start":427},{"file":"SKILL.md","line_end":429,"line_start":428},{"file":"SKILL.md","line_end":430,"line_start":429},{"file":"SKILL.md","line_end":436,"line_start":430},{"file":"SKILL.md","line_end":436,"line_start":436},{"file":"SKILL.md","line_end":437,"line_start":437},{"file":"SKILL.md","line_end":442,"line_start":442}]},{"factor":"filesystem","evidence":[{"file":"references/example-report.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":158,"line_start":158},{"file":"SKILL.md","line_end":162,"line_start":162},{"file":"SKILL.md","line_end":219,"line_start":219},{"file":"SKILL.md","line_end":226,"line_start":226},{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":240,"line_start":240},{"file":"SKILL.md","line_end":371,"line_start":371},{"file":"SKILL.md","line_end":434,"line_start":434},{"file":"SKILL.md","line_end":442,"line_start":442},{"file":"SKILL.md","line_end":477,"line_start":477},{"file":"SKILL.md","line_end":482,"line_start":482}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":226,"line_start":226}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Unpinned Remote Instruction Fetch","locations":[{"file":"SKILL.md","line_end":226,"line_start":226}],"confidence":0.82,"description":"SKILL.md line 226 tells the agent to fetch the runbook and other reference files from raw.githubusercontent.com on the main branch when local files are missing. This can load future instructions that were not part of the reviewed skill snapshot.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The instruction is explicit and tied to an unpinned main-branch URL. It is a supply-chain and instruction-integrity risk, although the URL points to the author repository."}],"low_findings":[{"title":"Persistent Audit Data Writes","locations":[{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":442,"line_start":442}],"confidence":0.86,"description":"SKILL.md lines 86-87 and 442 instruct the agent to store audit artifacts and promote veto issues into memory files. Domain audits can contain sensitive site, competitor, or penalty data, so persistence should be consented and scoped.","review_kind":"security","source_category":"semantic","source_severity":"low","confidence_reasoning":"The memory write behavior is directly stated in the skill contract and save-results section. The risk is low because paths are fixed, but the persisted content may be sensitive."}],"dangerous_patterns":[],"files_scanned":2,"total_lines":583,"audit_model":"codex","audited_at":"2026-07-04T15:58:43.279+00:00","created_at":"2026-07-05T00:39:26.145773+00:00","static_findings":[{"id":"external_commands:references/example-report.md:92:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"**Diagnosis**: Low CITE + unknown CORE-EEAT → Run `/aaron-marketing:seo-geo --mode audit` on top 5 l","category":"external_commands","line_end":96,"severity":"medium","line_start":92},{"id":"external_commands:references/example-report.md:96:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"- For entity building: run `entity-optimizer` to strengthen I-dimension signals","category":"external_commands","line_end":97,"severity":"medium","line_start":96},{"id":"external_commands:references/example-report.md:97:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"- For content audit: use `content-quality-auditor` on key pages","category":"external_commands","line_end":98,"severity":"medium","line_start":97},{"id":"external_commands:references/example-report.md:98:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"- For tracking progress: run `/aaron-marketing:seo-geo --mode track --report` with CITE score trends","category":"external_commands","line_end":99,"severity":"medium","line_start":98},{"id":"filesystem:references/example-report.md:3:path-traversal-sequence","file":"references/example-report.md","pattern":"Path traversal sequence","snippet":"Full example audit output for reference. See the [SKILL.md](../SKILL.md) for the complete workflow.","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":58,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":62,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":69,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":75,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":77,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":83,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: a CITE audit report, a citation-trust verdict, and a short handoff summary read","category":"external_commands","line_end":86,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing authority report plus a reusable summary that can be stored under `memor","category":"external_commands","line_end":87,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: veto items and domain risks to `memory/hot-cache.md` (auto-saved). Authority context","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Primary next skill**: use the `Next Best Skill` below once the trust picture is clear.","category":"external_commands","line_end":131,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":140,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Canonical source: `references/cite-domain-rating.md`. This inline copy is for convenience.","category":"external_commands","line_end":156,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":169,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":189,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":195,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":213,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":219,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Before scoring, `Read ../../../references/auditor-runbook.md`.** It is the authoritative, framewor","category":"external_commands","line_end":226,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","category":"external_commands","line_end":226,"severity":"medium","line_start":226},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[references/auditor-runbook.md §1](../../../references/auditor-runbook.md): `status`, `objective`,","category":"external_commands","line_end":231,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`key_findings`, `evidence_summary`, `recommended_next_skill`, plus the auditor fields `cap_applied`,","category":"external_commands","line_end":232,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`raw_overall_score` (CITE weighted `C×0.35 + I×0.20 + T×0.25 + E×0.20`, floor-rounded, before cap),","category":"external_commands","line_end":233,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and `final_overall_score`.","category":"external_commands","line_end":239,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> the **4-dimension weighted total** `C×0.35 + I×0.20 + T×0.25 + E×0.20`","category":"external_commands","line_end":245,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":260,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":264,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":279,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":285,"severity":"medium","line_start":279},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":302,"severity":"medium","line_start":285},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":317,"severity":"medium","line_start":302},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If context contradicts a neutral reading, state the exception in the finding's `evidence` field","category":"external_commands","line_end":335,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":371,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Render BEFORE \"Top 5 Priority Improvements\". Group, sort, and translate every `key_findings` entry p","category":"external_commands","line_end":371,"severity":"medium","line_start":371},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":382,"severity":"medium","line_start":373},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":426,"severity":"medium","line_start":382},{"id":"external_commands:SKILL.md:426:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For content improvement: use `content-quality-auditor` on key pages","category":"external_commands","line_end":427,"severity":"medium","line_start":426},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For backlink strategy: use `offsite-signal-analyzer` for detailed link analysis","category":"external_commands","line_end":428,"severity":"medium","line_start":427},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For competitor benchmarking: use `competitor-analysis` with CITE scores","category":"external_commands","line_end":429,"severity":"medium","line_start":428},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For tracking progress: run `/aaron-marketing:seo-geo --mode track --report` with CITE score trends","category":"external_commands","line_end":430,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":436,"severity":"medium","line_start":430},{"id":"external_commands:SKILL.md:436:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Cap Enforcement** (Runbook §2): walk the decision table. Identify which scenario matches your i","category":"external_commands","line_end":436,"severity":"medium","line_start":436},{"id":"external_commands:SKILL.md:437:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Artifact Gate Self-Check** (Runbook §4): run the 7-item checklist. If any item fails, force `st","category":"external_commands","line_end":437,"severity":"medium","line_start":437},{"id":"external_commands:SKILL.md:442:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Write the audit artifact to `memory/audits/domain/YYYY-MM-DD-<topic>.md` (the per-role path from [sk","category":"external_commands","line_end":442,"severity":"medium","line_start":442},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"13.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> Based on [CITE Domain Rating](https://github.com/aaron-he-zhu/cite-domain-rating). Full benchmark ","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:226:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","category":"network","line_end":226,"severity":"low","line_start":226},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Based on [CITE Domain Rating](https://github.com/aaron-he-zhu/cite-domain-rating). Full benchmark ","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:22:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Sister skill**: [content-quality-auditor](../../optimize/content-quality-auditor/SKILL.md) evaluat","category":"filesystem","line_end":22,"severity":"high","line_start":22},{"id":"filesystem:SKILL.md:51:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Start with one of these prompts. Finish with a citation-trust verdict and a handoff summary using th","category":"filesystem","line_end":51,"severity":"high","line_start":51},{"id":"filesystem:SKILL.md:93:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> See [CONNECTORS.md](../../../CONNECTORS.md) for tool category placeholders.","category":"filesystem","line_end":93,"severity":"high","line_start":93},{"id":"filesystem:SKILL.md:158:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"If any critical trust check triggers, flag it prominently at the top of the report using plain langu","category":"filesystem","line_end":158,"severity":"high","line_start":158},{"id":"filesystem:SKILL.md:162:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Evaluate each item against the criteria in [references/cite-domain-rating.md](../../../references/ci","category":"filesystem","line_end":162,"severity":"high","line_start":162},{"id":"filesystem:SKILL.md:219:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Before scoring, `Read ../../../references/auditor-runbook.md`.** It is the authoritative, framewor","category":"filesystem","line_end":219,"severity":"high","line_start":219},{"id":"filesystem:SKILL.md:226:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"*Standalone install fallback*: if that relative path does not exist, this skill was installed standa","category":"filesystem","line_end":226,"severity":"high","line_start":226},{"id":"filesystem:SKILL.md:231:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[references/auditor-runbook.md §1](../../../references/auditor-runbook.md): `status`, `objective`,","category":"filesystem","line_end":231,"severity":"high","line_start":231},{"id":"filesystem:SKILL.md:240:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> (see [cite-domain-rating.md](../../../references/cite-domain-rating.md)), floor-rounded, before th","category":"filesystem","line_end":240,"severity":"high","line_start":240},{"id":"filesystem:SKILL.md:371:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Render BEFORE \"Top 5 Priority Improvements\". Group, sort, and translate every `key_findings` entry p","category":"filesystem","line_end":371,"severity":"high","line_start":371},{"id":"filesystem:SKILL.md:434:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Execute in order, using the framework-agnostic procedure in [references/auditor-runbook.md](../../..","category":"filesystem","line_end":434,"severity":"high","line_start":434},{"id":"filesystem:SKILL.md:442:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Write the audit artifact to `memory/audits/domain/YYYY-MM-DD-<topic>.md` (the per-role path from [sk","category":"filesystem","line_end":442,"severity":"high","line_start":442},{"id":"filesystem:SKILL.md:477:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CITE Domain Rating](../../../references/cite-domain-rating.md) — Full 40-item benchmark with dime","category":"filesystem","line_end":477,"severity":"high","line_start":477},{"id":"filesystem:SKILL.md:482:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"CAUTIOUS + link-quality: [offsite-signal-analyzer](../offsite-signal-analyzer/SKILL.md). UNTRUSTED: ","category":"filesystem","line_end":482,"severity":"high","line_start":482},{"id":"blocker:SKILL.md:24:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"> **Namespace note**: CITE uses C01-C10 for Citation items; CORE-EEAT uses C01-C10 for Contextual Cl","category":"blocker","line_end":24,"severity":"low","line_start":24}],"finding_verdicts":[{"id":"external_commands:references/example-report.md:92:ruby-shell-backtick-execution","reason":"The flagged text is an example report line containing inline skill names or command text, not executable Ruby or shell code. No command is invoked automatically and no user-controlled shell construction is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/example-report.md:96:ruby-shell-backtick-execution","reason":"The flagged text is an example report line containing inline skill names or command text, not executable Ruby or shell code. No command is invoked automatically and no user-controlled shell construction is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/example-report.md:97:ruby-shell-backtick-execution","reason":"The flagged text is an example report line containing inline skill names or command text, not executable Ruby or shell code. No command is invoked automatically and no user-controlled shell construction is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/example-report.md:98:ruby-shell-backtick-execution","reason":"The flagged text is an example report line containing inline skill names or command text, not executable Ruby or shell code. No command is invoked automatically and no user-controlled shell construction is present.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/example-report.md:3:path-traversal-sequence","reason":"The ../ sequence appears in a Markdown link from the example report back to SKILL.md. It is documentation navigation, not filesystem traversal or a user-controlled file operation.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:373:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:426:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:427:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","reason":"The marker is a Markdown code fence or report template boundary, not a Ruby backtick expression. It defines user-facing examples and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:436:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:437:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:442:ruby-shell-backtick-execution","reason":"The backticks are Markdown inline formatting for paths, field names, formulas, or related skill names. There is no script body, subprocess call, or command interpolation at this location.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is metadata or a public reference citation in Markdown, not an automatic outbound request. No credentials, user data, or hidden network behavior are present at this location.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL is metadata or a public reference citation in Markdown, not an automatic outbound request. No credentials, user data, or hidden network behavior are present at this location.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:19:hardcoded-url","reason":"The URL is metadata or a public reference citation in Markdown, not an automatic outbound request. No credentials, user data, or hidden network behavior are present at this location.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:226:hardcoded-url","reason":"The hardcoded URL points to the same public repository and does not send secrets or user data. The integrity concern from fetching unpinned reference instructions is tracked separately as a semantic finding.","verdict":"false_positive","confidence":0.74},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:22:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:51:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:93:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:158:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:162:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:219:path-traversal-sequence","reason":"The path is a fixed repository-relative reference to the auditor runbook used by this skill family. It does not build a path from user input or request access to arbitrary files.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:226:path-traversal-sequence","reason":"The traversal sequence describes a fixed missing-file fallback for repository references, not arbitrary local path traversal. The separate risk of loading unpinned remote reference content is captured as a semantic finding.","verdict":"false_positive","confidence":0.78},{"id":"filesystem:SKILL.md:231:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:240:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:371:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:434:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:442:path-traversal-sequence","reason":"The flagged traversal appears in a Markdown link to skill-contract.md, while the instructed write path is bounded under memory/audits/domain. No user-controlled ../ path is constructed.","verdict":"false_positive","confidence":0.84},{"id":"filesystem:SKILL.md:477:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:482:path-traversal-sequence","reason":"The ../ sequence is part of a Markdown link to repository documentation or a sibling skill. It is a fixed documentation reference and not an exploitable path traversal operation.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:24:system-reconnaissance","reason":"The flagged phrase is a namespace note about CITE and CORE item identifiers. It does not instruct host, network, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Unpinned Remote Instruction Fetch","severity":"medium","locations":[{"file":"SKILL.md","line_end":226,"line_start":226}],"confidence":0.82,"description":"SKILL.md line 226 tells the agent to fetch the runbook and other reference files from raw.githubusercontent.com on the main branch when local files are missing. This can load future instructions that were not part of the reviewed skill snapshot.","confidence_reasoning":"The instruction is explicit and tied to an unpinned main-branch URL. It is a supply-chain and instruction-integrity risk, although the URL points to the author repository."},{"title":"Persistent Audit Data Writes","severity":"low","locations":[{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":442,"line_start":442}],"confidence":0.86,"description":"SKILL.md lines 86-87 and 442 instruct the agent to store audit artifacts and promote veto issues into memory files. Domain audits can contain sensitive site, competitor, or penalty data, so persistence should be consented and scoped.","confidence_reasoning":"The memory write behavior is directly stated in the skill contract and save-results section. The risk is low because paths are fixed, but the persisted content may be sensitive."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}