{"data":{"skill":{"slug":"aaron-he-zhu-domain-authority-auditor","name":"domain-authority-auditor","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/domain-authority-auditor","status":"approved","author":"aaron-he-zhu","authorVersion":"17.0.0","skillstoreRevision":1},"audit":{"id":"5c4af3f6-4ae8-41cd-a913-afa578235e81","skill_id":"67470902-f698-45c1-b1be-85a7065f4386","version":5,"content_hash":"v3:d71c7417a35d5c2624161bd2fe8de8a41a362128:c3e51b44e8eb4d8c087a16f5048989fe63452c44774d8bc1348319b17b0d2009:b0019a3bc19af6720d511889d34f2385f5255171dd693b18967cb03ac204d785:736b696c6c732f6161726f6e2d68652d7a68752f646f6d61696e2d617574686f726974792d61756469746f72:4bf417ea73ba87966e11995cadf9fc64","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 42 static alerts are false positives caused by Markdown formatting, fixed documentation paths, metadata URLs, or constrained repository commands. No prompt injection, unsafe command construction, unauthorized persistence, or malicious intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/example-report.md","line_end":96,"line_start":92},{"file":"references/example-report.md","line_end":97,"line_start":96},{"file":"references/example-report.md","line_end":98,"line_start":97},{"file":"references/example-report.md","line_end":99,"line_start":98},{"file":"SKILL.md","line_end":32,"line_start":29},{"file":"SKILL.md","line_end":36,"line_start":32},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":71,"line_start":55},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":76,"line_start":75},{"file":"SKILL.md","line_end":77,"line_start":76},{"file":"SKILL.md","line_end":81,"line_start":77},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":97,"line_start":85},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":108,"line_start":106},{"file":"SKILL.md","line_end":120,"line_start":108},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":126,"line_start":124},{"file":"SKILL.md","line_end":128,"line_start":126},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":44,"line_start":44}]},{"factor":"filesystem","evidence":[{"file":"references/example-report.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":145,"line_start":145},{"file":"SKILL.md","line_end":146,"line_start":146},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":152,"line_start":152},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":44,"line_start":44}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":14,"line_start":14}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":516,"audit_model":"codex","audited_at":"2026-07-12T11:59:21.121+00:00","created_at":"2026-07-14T15:53:58.837073+00:00","static_findings":[{"id":"external_commands:references/example-report.md:92:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"**Diagnosis**: Low CITE + unknown CORE-EEAT → Run `/aaron-marketing:seo-geo --mode audit` on top 5 l","category":"external_commands","line_end":96,"severity":"medium","line_start":92},{"id":"external_commands:references/example-report.md:96:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"- For entity building: run `entity-optimizer` to strengthen I-dimension signals","category":"external_commands","line_end":97,"severity":"medium","line_start":96},{"id":"external_commands:references/example-report.md:97:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"- For content audit: use `content-quality-auditor` on key pages","category":"external_commands","line_end":98,"severity":"medium","line_start":97},{"id":"external_commands:references/example-report.md:98:ruby-shell-backtick-execution","file":"references/example-report.md","pattern":"Ruby/shell backtick execution","snippet":"- For tracking progress: run `/aaron-marketing:seo-geo --mode track --report` with CITE score trends","category":"external_commands","line_end":99,"severity":"medium","line_start":98},{"id":"filesystem:references/example-report.md:3:path-traversal-sequence","file":"references/example-report.md","pattern":"Path traversal sequence","snippet":"Full example audit output for reference. See the [SKILL.md](../SKILL.md) for the complete workflow.","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":32,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":36,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `offsite-signal-analyzer` for link diagnosis without a gate, `content-quality-auditor` for one p","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read `../../../references/auditor-runbook.md`, `scoring-semantics.md`, `cite-domain-rating.md`, and ","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- domain type/profile: `default`, `content-publisher`, `product-service`, `ecommerce`, `community-ug","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Without peer cohort, market, stage, or domain type, return `NEEDS_INPUT/UNDECIDED`; the inherited nu","category":"external_commands","line_end":71,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Evaluate all 40 IDs against the declared cohort. Tool estimates remain `estimated` or `proxy`; us","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CITE-T03`: material link/traffic incoherence plus corroborating manipulation evidence relative to","category":"external_commands","line_end":76,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CITE-T05`: verified manipulation network after common-source/ecosystem adjustment.","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CITE-T09`: verified active manual action or material unresolved deindexing.","category":"external_commands","line_end":81,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create a typed `audit-run.schema.json` input and execute `python3 \"$AARON_SKILLS_ROOT/scripts/rubric","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Lead with verdict, profile/cohort/target/date, score or `NOT_SCORED` coverage/interval, and confiden","category":"external_commands","line_end":97,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete, no veto, healthy score/no failures: `DONE` + `SHIP`.","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete, remediation needed or one veto: `DONE_WITH_CONCERNS` + `FIX`; one veto caps final at 59.","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete, 2+ verified vetoes: `DONE` + `BLOCK`; no final score.","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Missing applicable/cohort evidence: `NEEDS_INPUT` + `UNDECIDED`; no score.","category":"external_commands","line_end":100,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Route link investigation to `offsite-signal-analyzer`, technical/index evidence to `technical-seo-ch","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Complete product-service profile, raw 78, one verified T09 failure: `DONE_WITH_CONCERNS/FIX`, fina","category":"external_commands","line_end":108,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Verified T03 and T05 failures with complete evidence: `DONE/BLOCK`, raw retained, no final score.","category":"external_commands","line_end":120,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use plain descriptions by default. On a trace request, show `CITE-T03`, `CITE-T05`, and `CITE-T09` w","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Persist only after explicit authorization. Assemble the complete v3 draft, validate it against the i","category":"external_commands","line_end":126,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":128,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:44:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"Read `../../../references/auditor-runbook.md`, `scoring-semantics.md`, `cite-domain-rating.md`, and ","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:44:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"Read `../../../references/auditor-runbook.md`, `scoring-semantics.md`, `cite-domain-rating.md`, and ","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"17.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"filesystem:SKILL.md:44:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Read `../../../references/auditor-runbook.md`, `scoring-semantics.md`, `cite-domain-rating.md`, and ","category":"filesystem","line_end":44,"severity":"high","line_start":44},{"id":"filesystem:SKILL.md:143:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CITE benchmark](../../../references/cite-domain-rating.md)","category":"filesystem","line_end":143,"severity":"high","line_start":143},{"id":"filesystem:SKILL.md:144:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Auditor runbook](../../../references/auditor-runbook.md)","category":"filesystem","line_end":144,"severity":"high","line_start":144},{"id":"filesystem:SKILL.md:145:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Scoring semantics](../../../references/scoring-semantics.md)","category":"filesystem","line_end":145,"severity":"high","line_start":145},{"id":"filesystem:SKILL.md:146:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Offsite signal analyzer](../offsite-signal-analyzer/SKILL.md)","category":"filesystem","line_end":146,"severity":"high","line_start":146},{"id":"filesystem:SKILL.md:150:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Investigate links:** [offsite-signal-analyzer](../offsite-signal-analyzer/SKILL.md)","category":"filesystem","line_end":150,"severity":"high","line_start":150},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Repair entity state:** [entity-optimizer](../../../protocol/entity-optimizer/SKILL.md)","category":"filesystem","line_end":151,"severity":"high","line_start":151},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Verify technical/index state:** [technical-seo-checker](../../optimize/technical-seo-checker/SKI","category":"filesystem","line_end":152,"severity":"high","line_start":152},{"id":"filesystem:SKILL.md:153:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Audit representative content:** [content-quality-auditor](../../optimize/content-quality-auditor","category":"filesystem","line_end":153,"severity":"high","line_start":153},{"id":"filesystem:SKILL.md:44:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"Read `../../../references/auditor-runbook.md`, `scoring-semantics.md`, `cite-domain-rating.md`, and ","category":"filesystem","line_end":44,"severity":"low","line_start":44},{"id":"blocker:SKILL.md:135:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- All 40 IDs have evidence-backed state, Unknown, or valid N/A.","category":"blocker","line_end":135,"severity":"low","line_start":135}],"finding_verdicts":[{"id":"external_commands:references/example-report.md:92:ruby-shell-backtick-execution","reason":"The backticks format a slash-command example in Markdown. They are not Ruby execution syntax or an executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/example-report.md:96:ruby-shell-backtick-execution","reason":"The backticks mark the entity-optimizer skill name as inline Markdown. No command execution mechanism is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/example-report.md:97:ruby-shell-backtick-execution","reason":"The backticks mark the content-quality-auditor skill name as inline Markdown. They do not execute a process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/example-report.md:98:ruby-shell-backtick-execution","reason":"The text is a formatted slash-command example inside an example report. It contains no Ruby or shell execution primitive.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/example-report.md:3:path-traversal-sequence","reason":"The sequence is a constant Markdown link to the parent SKILL.md. It neither accepts user-controlled paths nor performs filesystem access.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"Line 29 opens a fenced text example. Markdown fence delimiters do not execute Ruby or shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"Line 32 closes a fenced text example. It is documentation syntax without an execution path.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks format related skill names in prose. No command interpreter or subprocess call consumes them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The backticks are Markdown delimiters around paths, values, and a fixed setup expression. They are not Ruby backtick operators.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The backticks format an enumerated list of domain profile values. These values are data labels, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The backticks format status values in explanatory prose. No executable syntax or process invocation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks identify evidence-state labels. They are Markdown formatting and cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backticks format the CITE-T03 rubric identifier. The line only defines an audit condition.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The backticks format the CITE-T05 rubric identifier. No command or dynamic code is executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The backticks format the CITE-T09 rubric identifier. The surrounding text is an audit rule.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The backticks delimit a documented Python invocation, not Ruby execution. Its script path is fixed, its root is quoted, and the input is an argument.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The backticks format the NOT_SCORED status label. There is no external command at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The backticks format report statuses and verdicts. They are output vocabulary rather than executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The marked text contains canonical audit output labels. Markdown formatting does not create a shell execution path.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The backticks identify DONE and BLOCK verdict values. They are plain report data.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The backticks identify NEEDS_INPUT and UNDECIDED output values. No interpreter evaluates them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The backticks format related skill names used for routing. They are not process invocations.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The backticks format worked-example status values. The line documents scoring behavior only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks format a worked-example verdict. There is no external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks format three CITE identifiers requested for trace output. They are static labels.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The backticks format a constrained relative artifact path. The text explicitly requires authorization and validation before persistence.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The matched backticks open a Bash documentation fence. The contained validator uses a fixed quoted script path and positional file arguments.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:44:shell-command-substitution","reason":"The substitution runs only a fixed git rev-parse command to locate the repository root. It suppresses errors, accepts no user input, and its result is quoted.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:44:template-literal-with-command-substitution","reason":"This is a documented shell assignment inside Markdown, not a JavaScript template literal. No application code evaluates a dynamic template.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is homepage metadata for the public source repository. The skill does not send a request or transmit data to it.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL appears in package metadata as the project homepage. It is not used by any network operation.","verdict":"false_positive","confidence":1},{"id":"filesystem:SKILL.md:44:path-traversal-sequence","reason":"The constant relative paths identify versioned repository documentation required by the skill. They contain no user-controlled segment, and standalone mode uses the bundled runtime.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:143:path-traversal-sequence","reason":"This is a constant Markdown link to the repository CITE benchmark. It does not construct or access an arbitrary path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:144:path-traversal-sequence","reason":"This is a constant Markdown reference to the repository auditor runbook. No user input controls the path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:145:path-traversal-sequence","reason":"This fixed Markdown link points to repository scoring documentation. It is not an arbitrary filesystem traversal.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:146:path-traversal-sequence","reason":"The relative link names a neighboring skill document. It is static documentation without a user-controlled path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:150:path-traversal-sequence","reason":"The link statically routes users to a neighboring link-analysis skill. It cannot escape through attacker-supplied path components.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","reason":"The fixed relative link references the repository entity-optimizer skill. It is documentation, not unsafe path handling.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","reason":"The fixed relative link references the repository technical SEO skill. No path is derived from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:153:path-traversal-sequence","reason":"The fixed relative link references the repository content audit skill. It does not perform arbitrary filesystem access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:44:standard-device-file-access","reason":"The only device path is /dev/null used to suppress git error output. It neither reads sensitive device data nor writes persistent content.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:135:system-reconnaissance","reason":"The word IDs refers to the 40 CITE rubric identifiers. The checkpoint does not inspect system users, processes, hardware, or configuration.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","subject_content_hash":"c3e51b44e8eb4d8c087a16f5048989fe63452c44774d8bc1348319b17b0d2009","subject_tree_hash":"b0019a3bc19af6720d511889d34f2385f5255171dd693b18967cb03ac204d785","subject_plugin_path":"skills/aaron-he-zhu/domain-authority-auditor","audit_payload_hash":"4bf417ea73ba87966e11995cadf9fc64","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","contentHash":"c3e51b44e8eb4d8c087a16f5048989fe63452c44774d8bc1348319b17b0d2009","treeHash":"b0019a3bc19af6720d511889d34f2385f5255171dd693b18967cb03ac204d785","pluginPath":"skills/aaron-he-zhu/domain-authority-auditor","auditPayloadHash":"4bf417ea73ba87966e11995cadf9fc64"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}