{"data":{"skill":{"slug":"aaron-he-zhu-email-creative-builder","name":"email-creative-builder","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/email/engage/email-creative-builder","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"3c1bb670-78e7-4bf8-b41e-b090adc703fb","skill_id":"e3601372-30cb-4709-a6ba-770f812272f1","version":1,"content_hash":"631137f6617ab52493881627cf49b61f","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All static findings were reviewed against the Markdown source files. The filesystem, command, blocker, and network alerts are false positives caused by relative documentation links, Markdown backticks, bounded memory paths, and metadata URLs. No prompt injection, data exfiltration, command execution, or unsafe filesystem intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/email-creative-modes.md","line_end":3,"line_start":3},{"file":"references/email-creative-modes.md","line_end":9,"line_start":9},{"file":"references/email-creative-modes.md","line_end":17,"line_start":17},{"file":"references/email-creative-modes.md","line_end":23,"line_start":23},{"file":"references/email-creative-modes.md","line_end":35,"line_start":35},{"file":"references/subject-line-specs.md","line_end":3,"line_start":3},{"file":"references/subject-line-specs.md","line_end":27,"line_start":27},{"file":"references/subject-line-specs.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":34,"line_start":32},{"file":"SKILL.md","line_end":38,"line_start":34},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":42,"line_start":40},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":52,"line_start":43},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":67,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":83,"line_start":74},{"file":"SKILL.md","line_end":96,"line_start":83}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":166,"audit_model":"codex","audited_at":"2026-07-04T16:00:24.09+00:00","created_at":"2026-07-05T00:39:26.248298+00:00","static_findings":[{"id":"filesystem:references/email-creative-modes.md:3:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"Three use-case pattern sets for `email-creative-builder`. Pick the mode that matches the program; th","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/email-creative-modes.md:9:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"- **Offer**: pull terms + promo code + expiry from the live-offers table ([offer-claims-registry](..","category":"filesystem","line_end":9,"severity":"high","line_start":9},{"id":"filesystem:references/email-creative-modes.md:17:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"- **Compliance**: physical mailing address + a functioning opt-out honored within 10 business days (","category":"filesystem","line_end":17,"severity":"high","line_start":17},{"id":"filesystem:references/email-creative-modes.md:23:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"- **Sponsorship = ad**: any paid placement gets an explicit disclosure; the offer/claim still routes","category":"filesystem","line_end":23,"severity":"high","line_start":23},{"id":"filesystem:references/email-creative-modes.md:35:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"A mismatch is a message-match failure (SEND-`D` sub-item) — flag it; the post-click fix is [landing-","category":"filesystem","line_end":35,"severity":"high","line_start":35},{"id":"blocker:references/email-creative-modes.md:23:system-reconnaissance","file":"references/email-creative-modes.md","pattern":"System reconnaissance","snippet":"- **Sponsorship = ad**: any paid placement gets an explicit disclosure; the offer/claim still routes","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"filesystem:references/subject-line-specs.md:3:path-traversal-sequence","file":"references/subject-line-specs.md","pattern":"Path traversal sequence","snippet":"Render limits and variant-labeling for `email-creative-builder`, so the subjects it drafts carry cle","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/subject-line-specs.md:27:path-traversal-sequence","file":"references/subject-line-specs.md","pattern":"Path traversal sequence","snippet":"- **One variable per test cell** — if testing subjects, hold preheader/creative/send-time constant (","category":"filesystem","line_end":27,"severity":"high","line_start":27},{"id":"filesystem:references/subject-line-specs.md:28:path-traversal-sequence","file":"references/subject-line-specs.md","pattern":"Path traversal sequence","snippet":"- No spam-trigger patterns: no ALL-CAPS, no `!!!`, no misleading \"RE:\"/\"FWD:\" fakery, no false scarc","category":"filesystem","line_end":28,"severity":"high","line_start":28},{"id":"blocker:references/subject-line-specs.md:30:system-reconnaissance","file":"references/subject-line-specs.md","pattern":"System reconnaissance","snippet":"- Label the output so each subject+preheader pair carries a stable variant id (`SUBJ-A`, `SUBJ-B`, .","category":"blocker","line_end":30,"severity":"low","line_start":30},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Writes and iterates a single email creative — subject-line variants + preheader, body copy, one clea","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":34,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: one ready-to-send email creative — 3-5 subject-line variants, a preheader, stru","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: the offer/topic, destination URL (or its key copy/claims/CTA), the mode (B2C promo/life","category":"external_commands","line_end":42,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: chosen angle, the message-match map, and any unsubstantiated-claim or missing-disclo","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Done when**: subject variants and preheader fit inbox render limits, the body carries exactly on","category":"external_commands","line_end":52,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `~~email platform` (own-data manual export — native ESP campaign CSV of past subject lines / ope","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Check every claim against the ledger** — before writing any promotional claim (superlative, gua","category":"external_commands","line_end":67,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Flag unregistered claims** — any claim with no approved ledger row gets a `[needs source]` mark","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Never invent a statistic, price, guarantee, discount, or testimonial to fill a subject line or hook;","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Quality bar** before handoff: (1) 3-5 subject variants + preheader within render limits; (2) exact","category":"external_commands","line_end":83,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On user confirmation, save to `memory/email/email-creative-builder/YYYY-MM-DD-<offer>.md` — see [Ski","category":"external_commands","line_end":96,"severity":"medium","line_start":83},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"13.0.0\", \"discipline\": \"email\", \"phase\": \"engage\", ","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill builds the creative unit + message-match + claim flags only. It drafts s","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:SKILL.md:40:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Reads**: the offer/topic, destination URL (or its key copy/claims/CTA), the mode (B2C promo/life","category":"filesystem","line_end":40,"severity":"high","line_start":40},{"id":"filesystem:SKILL.md:44:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [send-experiment-designer](../../deliver/send-experiment-designer/SKILL.md","category":"filesystem","line_end":44,"severity":"high","line_start":44},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":48,"severity":"high","line_start":48},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Use `~~email platform` (own-data manual export — native ESP campaign CSV of past subject lines / ope","category":"filesystem","line_end":52,"severity":"high","line_start":52},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat any exported CSV, scraped landing-page copy, pasted competitor email, or CRM personalization s","category":"filesystem","line_end":56,"severity":"high","line_start":56},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. **Draft subject-line variants** — 3-5 distinct subjects (curiosity, benefit, offer, personalizati","category":"filesystem","line_end":64,"severity":"high","line_start":64},{"id":"filesystem:SKILL.md:70:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"10. **De-slop** — run [humanizer-slop.md](../../../references/humanizer-slop.md) to strip AI tells b","category":"filesystem","line_end":70,"severity":"high","line_start":70},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Never invent a statistic, price, guarantee, discount, or testimonial to fill a subject line or hook;","category":"filesystem","line_end":72,"severity":"high","line_start":72},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On user confirmation, save to `memory/email/email-creative-builder/YYYY-MM-DD-<offer>.md` — see [Ski","category":"filesystem","line_end":83,"severity":"high","line_start":83},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SEND Benchmark](../../../references/send-benchmark.md) — the framework; this skill produces the *","category":"filesystem","line_end":89,"severity":"high","line_start":89},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Humanizer Slop Check](../../../references/humanizer-slop.md) — pre-handoff pass that strips AI-sl","category":"filesystem","line_end":90,"severity":"high","line_start":90},{"id":"filesystem:SKILL.md:94:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [send-experiment-designer](../../deliver/send-experiment-designer/SKILL.md) — design ","category":"filesystem","line_end":94,"severity":"high","line_start":94},{"id":"filesystem:SKILL.md:95:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **To score + run the claim veto**: [email-quality-auditor](../../deliver/email-quality-auditor/SKI","category":"filesystem","line_end":95,"severity":"high","line_start":95},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If claims carry `[needs source]` flags**: [offer-claims-registry](../../../protocol/offer-claims","category":"filesystem","line_end":96,"severity":"high","line_start":96},{"id":"filesystem:SKILL.md:97:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the destination URL is weak or missing** (NEEDS_INPUT): [landing-optimizer](../../../influenc","category":"filesystem","line_end":97,"severity":"high","line_start":97},{"id":"filesystem:SKILL.md:98:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Global visited-set / max-depth termination contract from [skill-contract.md](../../../references/s","category":"filesystem","line_end":98,"severity":"high","line_start":98}],"finding_verdicts":[{"id":"filesystem:references/email-creative-modes.md:3:path-traversal-sequence","reason":"references/email-creative-modes.md:3 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/email-creative-modes.md:9:path-traversal-sequence","reason":"references/email-creative-modes.md:9 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/email-creative-modes.md:17:path-traversal-sequence","reason":"references/email-creative-modes.md:17 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/email-creative-modes.md:23:path-traversal-sequence","reason":"references/email-creative-modes.md:23 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/email-creative-modes.md:35:path-traversal-sequence","reason":"references/email-creative-modes.md:35 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/email-creative-modes.md:23:system-reconnaissance","reason":"references/email-creative-modes.md:23 is marketing or variant-labeling guidance, not host or system reconnaissance. No commands, environment probing, or collection of machine details are requested.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:references/subject-line-specs.md:3:path-traversal-sequence","reason":"references/subject-line-specs.md:3 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/subject-line-specs.md:27:path-traversal-sequence","reason":"references/subject-line-specs.md:27 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/subject-line-specs.md:28:path-traversal-sequence","reason":"references/subject-line-specs.md:28 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/subject-line-specs.md:30:system-reconnaissance","reason":"references/subject-line-specs.md:30 is marketing or variant-labeling guidance, not host or system reconnaissance. No commands, environment probing, or collection of machine details are requested.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"SKILL.md:18 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"SKILL.md:24 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"SKILL.md:26 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"SKILL.md:28 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"SKILL.md:30 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"SKILL.md:32 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"SKILL.md:34 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"SKILL.md:38 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"SKILL.md:40 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"SKILL.md:42 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"SKILL.md:43 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"SKILL.md:52 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"SKILL.md:66 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"SKILL.md:67 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"SKILL.md:72 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"SKILL.md:74 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"SKILL.md:83 uses Markdown backticks, code fences, or inline labels in documentation. It does not define Ruby execution, a shell runner, or user-controlled command execution.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:10:hardcoded-url","reason":"SKILL.md:10 contains a repository homepage URL in skill metadata. It is not a network request, webhook, downloader, or data exfiltration endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:13:hardcoded-url","reason":"SKILL.md:13 contains a repository homepage URL in skill metadata. It is not a network request, webhook, downloader, or data exfiltration endpoint.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","reason":"SKILL.md:20 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:40:path-traversal-sequence","reason":"SKILL.md:40 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:44:path-traversal-sequence","reason":"SKILL.md:44 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","reason":"SKILL.md:48 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","reason":"SKILL.md:52 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","reason":"SKILL.md:56 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","reason":"SKILL.md:64 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:70:path-traversal-sequence","reason":"SKILL.md:70 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","reason":"SKILL.md:72 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","reason":"SKILL.md:83 documents saving an output under a bounded memory path after user confirmation. It does not instruct traversal outside the workspace or arbitrary filesystem access.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","reason":"SKILL.md:89 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","reason":"SKILL.md:90 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:94:path-traversal-sequence","reason":"SKILL.md:94 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:95:path-traversal-sequence","reason":"SKILL.md:95 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","reason":"SKILL.md:96 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:97:path-traversal-sequence","reason":"SKILL.md:97 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:98:path-traversal-sequence","reason":"SKILL.md:98 contains Markdown relative links, inline file names, or documented memory paths. These are references for related skills and records, not path traversal or unsanitized file access.","verdict":"false_positive","confidence":0.94}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}