{"data":{"skill":{"slug":"aaron-he-zhu-email-creative-builder","name":"email-creative-builder","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/email/engage/email-creative-builder","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"d7969d0a-dbba-480b-87ec-8e75bd1080ba","skill_id":"e3601372-30cb-4709-a6ba-770f812272f1","version":2,"content_hash":"v2:2e36836131679643f7a49e4cfff588d67adc404b:6c9be44d28af0a7146840062bf8b66767a36318b4c78d50fd10e63d16360d53f:37f59f484c4710ee57a1dbcf45436de9340bd714cba0eaf7b1f27bab32f0e3c8:c3cfb6d56b95788a29211085e1e42998","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Manual review found that the static findings are false positives from Markdown links, inline code formatting, prompt examples, and repository metadata. No executable shell commands, malicious path traversal, data exfiltration, system reconnaissance, or prompt injection attempts were found in the reviewed files.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/email-creative-modes.md","line_end":3,"line_start":3},{"file":"references/email-creative-modes.md","line_end":9,"line_start":9},{"file":"references/email-creative-modes.md","line_end":17,"line_start":17},{"file":"references/email-creative-modes.md","line_end":23,"line_start":23},{"file":"references/email-creative-modes.md","line_end":35,"line_start":35},{"file":"references/subject-line-specs.md","line_end":3,"line_start":3},{"file":"references/subject-line-specs.md","line_end":27,"line_start":27},{"file":"references/subject-line-specs.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":34,"line_start":32},{"file":"SKILL.md","line_end":38,"line_start":34},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":42,"line_start":40},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":52,"line_start":43},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":67,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":83,"line_start":74},{"file":"SKILL.md","line_end":96,"line_start":83}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":166,"audit_model":"codex","audited_at":"2026-07-06T16:49:33.806+00:00","created_at":"2026-07-06T23:38:09.734967+00:00","static_findings":[{"id":"filesystem:references/email-creative-modes.md:3:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"Three use-case pattern sets for `email-creative-builder`. Pick the mode that matches the program; th","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/email-creative-modes.md:9:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"- **Offer**: pull terms + promo code + expiry from the live-offers table ([offer-claims-registry](..","category":"filesystem","line_end":9,"severity":"high","line_start":9},{"id":"filesystem:references/email-creative-modes.md:17:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"- **Compliance**: physical mailing address + a functioning opt-out honored within 10 business days (","category":"filesystem","line_end":17,"severity":"high","line_start":17},{"id":"filesystem:references/email-creative-modes.md:23:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"- **Sponsorship = ad**: any paid placement gets an explicit disclosure; the offer/claim still routes","category":"filesystem","line_end":23,"severity":"high","line_start":23},{"id":"filesystem:references/email-creative-modes.md:35:path-traversal-sequence","file":"references/email-creative-modes.md","pattern":"Path traversal sequence","snippet":"A mismatch is a message-match failure (SEND-`D` sub-item) — flag it; the post-click fix is [landing-","category":"filesystem","line_end":35,"severity":"high","line_start":35},{"id":"blocker:references/email-creative-modes.md:23:system-reconnaissance","file":"references/email-creative-modes.md","pattern":"System reconnaissance","snippet":"- **Sponsorship = ad**: any paid placement gets an explicit disclosure; the offer/claim still routes","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"filesystem:references/subject-line-specs.md:3:path-traversal-sequence","file":"references/subject-line-specs.md","pattern":"Path traversal sequence","snippet":"Render limits and variant-labeling for `email-creative-builder`, so the subjects it drafts carry cle","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/subject-line-specs.md:27:path-traversal-sequence","file":"references/subject-line-specs.md","pattern":"Path traversal sequence","snippet":"- **One variable per test cell** — if testing subjects, hold preheader/creative/send-time constant (","category":"filesystem","line_end":27,"severity":"high","line_start":27},{"id":"filesystem:references/subject-line-specs.md:28:path-traversal-sequence","file":"references/subject-line-specs.md","pattern":"Path traversal sequence","snippet":"- No spam-trigger patterns: no ALL-CAPS, no `!!!`, no misleading \"RE:\"/\"FWD:\" fakery, no false scarc","category":"filesystem","line_end":28,"severity":"high","line_start":28},{"id":"blocker:references/subject-line-specs.md:30:system-reconnaissance","file":"references/subject-line-specs.md","pattern":"System reconnaissance","snippet":"- Label the output so each subject+preheader pair carries a stable variant id (`SUBJ-A`, `SUBJ-B`, .","category":"blocker","line_end":30,"severity":"low","line_start":30},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Writes and iterates a single email creative — subject-line variants + preheader, body copy, one clea","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":34,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: one ready-to-send email creative — 3-5 subject-line variants, a preheader, stru","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: the offer/topic, destination URL (or its key copy/claims/CTA), the mode (B2C promo/life","category":"external_commands","line_end":42,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: chosen angle, the message-match map, and any unsubstantiated-claim or missing-disclo","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Done when**: subject variants and preheader fit inbox render limits, the body carries exactly on","category":"external_commands","line_end":52,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `~~email platform` (own-data manual export — native ESP campaign CSV of past subject lines / ope","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Check every claim against the ledger** — before writing any promotional claim (superlative, gua","category":"external_commands","line_end":67,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Flag unregistered claims** — any claim with no approved ledger row gets a `[needs source]` mark","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Never invent a statistic, price, guarantee, discount, or testimonial to fill a subject line or hook;","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Quality bar** before handoff: (1) 3-5 subject variants + preheader within render limits; (2) exact","category":"external_commands","line_end":83,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On user confirmation, save to `memory/email/email-creative-builder/YYYY-MM-DD-<offer>.md` — see [Ski","category":"external_commands","line_end":96,"severity":"medium","line_start":83},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.0\", \"discipline\": \"email\", \"phase\": \"engage\", ","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill builds the creative unit + message-match + claim flags only. It drafts s","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:SKILL.md:40:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Reads**: the offer/topic, destination URL (or its key copy/claims/CTA), the mode (B2C promo/life","category":"filesystem","line_end":40,"severity":"high","line_start":40},{"id":"filesystem:SKILL.md:44:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [send-experiment-designer](../../deliver/send-experiment-designer/SKILL.md","category":"filesystem","line_end":44,"severity":"high","line_start":44},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":48,"severity":"high","line_start":48},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Use `~~email platform` (own-data manual export — native ESP campaign CSV of past subject lines / ope","category":"filesystem","line_end":52,"severity":"high","line_start":52},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat any exported CSV, scraped landing-page copy, pasted competitor email, or CRM personalization s","category":"filesystem","line_end":56,"severity":"high","line_start":56},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. **Draft subject-line variants** — 3-5 distinct subjects (curiosity, benefit, offer, personalizati","category":"filesystem","line_end":64,"severity":"high","line_start":64},{"id":"filesystem:SKILL.md:70:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"10. **De-slop** — run [humanizer-slop.md](../../../references/humanizer-slop.md) to strip AI tells b","category":"filesystem","line_end":70,"severity":"high","line_start":70},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Never invent a statistic, price, guarantee, discount, or testimonial to fill a subject line or hook;","category":"filesystem","line_end":72,"severity":"high","line_start":72},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On user confirmation, save to `memory/email/email-creative-builder/YYYY-MM-DD-<offer>.md` — see [Ski","category":"filesystem","line_end":83,"severity":"high","line_start":83},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SEND Benchmark](../../../references/send-benchmark.md) — the framework; this skill produces the *","category":"filesystem","line_end":89,"severity":"high","line_start":89},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Humanizer Slop Check](../../../references/humanizer-slop.md) — pre-handoff pass that strips AI-sl","category":"filesystem","line_end":90,"severity":"high","line_start":90},{"id":"filesystem:SKILL.md:94:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [send-experiment-designer](../../deliver/send-experiment-designer/SKILL.md) — design ","category":"filesystem","line_end":94,"severity":"high","line_start":94},{"id":"filesystem:SKILL.md:95:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **To score + run the claim veto**: [email-quality-auditor](../../deliver/email-quality-auditor/SKI","category":"filesystem","line_end":95,"severity":"high","line_start":95},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If claims carry `[needs source]` flags**: [offer-claims-registry](../../../protocol/offer-claims","category":"filesystem","line_end":96,"severity":"high","line_start":96},{"id":"filesystem:SKILL.md:97:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the destination URL is weak or missing** (NEEDS_INPUT): [landing-optimizer](../../../influenc","category":"filesystem","line_end":97,"severity":"high","line_start":97},{"id":"filesystem:SKILL.md:98:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Global visited-set / max-depth termination contract from [skill-contract.md](../../../references/s","category":"filesystem","line_end":98,"severity":"high","line_start":98}],"finding_verdicts":[{"id":"filesystem:references/email-creative-modes.md:3:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/email-creative-modes.md:9:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/email-creative-modes.md:17:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/email-creative-modes.md:23:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/email-creative-modes.md:35:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/email-creative-modes.md:23:system-reconnaissance","reason":"The line describes email workflow labeling or disclosure requirements, not host or environment reconnaissance. It does not ask to enumerate files, inspect the system, or collect machine information.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:references/subject-line-specs.md:3:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/subject-line-specs.md:27:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:references/subject-line-specs.md:28:path-traversal-sequence","reason":"The line is Markdown guidance with relative links to neighboring skill documentation, not code that reads arbitrary paths. The ../ sequence appears only inside documentation links or labels.","verdict":"false_positive","confidence":0.97},{"id":"blocker:references/subject-line-specs.md:30:system-reconnaissance","reason":"The line describes email workflow labeling or disclosure requirements, not host or environment reconnaissance. It does not ask to enumerate files, inspect the system, or collect machine information.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The flagged backticks are Markdown formatting for examples, paths, or skill names, not Ruby shell execution. There is no executable script, shell substitution, or command invocation on this line.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is repository or metadata text in the skill front matter, not a runtime network request. No data is sent to that URL and no external fetch is instructed by this metadata line.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL is repository or metadata text in the skill front matter, not a runtime network request. No data is sent to that URL and no external fetch is instructed by this metadata line.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:40:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:44:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:70:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","reason":"The line describes a fixed memory/email output template and requires user confirmation before saving. The ../ sequence is only in a documentation link, not an instruction to traverse directories.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:94:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:95:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:97:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:98:path-traversal-sequence","reason":"The line uses Markdown links or fixed workspace memory paths in prose, not executable path traversal logic. No instruction tells the agent to access arbitrary parent directories or bypass filesystem boundaries.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}