{"data":{"skill":{"slug":"aaron-he-zhu-list-hygiene-monitor","name":"list-hygiene-monitor","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/email/setup/list-hygiene-monitor","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"cc6a282f-16f4-42b4-8ab0-7a5cac2d3e20","skill_id":"5740b444-d9d1-467c-8015-85dc2bf220f6","version":5,"content_hash":"v2:b9e5ae9c7a884b8b0bc6894c293164039a0aa79d:504c7b230e835b36089010c977122089a94993782d1763e21472455657ccf588:7e3eccb0dfccb898484a120e2851f1e93998c4e71d0cda7ef3f1b731551b00af:4305f4da5c64fc9a438323b7d7c252bc","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most findings are false positives caused by Markdown formatting and fixed repository-relative links. Two findings are confirmed: line 52 uses an unquoted user-derived command argument, and line 70 creates a save path from an unsanitized value. No prompt injection or malicious exfiltration intent was found.","remediation":[{"issue":"The connector command accepts an unquoted list placeholder that may contain shell metacharacters.","severity":"medium","suggestion":"Validate list names, pass them as quoted arguments, and avoid shell interpolation when invoking connector or ledger scripts."},{"issue":"The save filename includes an unsanitized list or topic value.","severity":"high","suggestion":"Slugify the value, reject separators and dot segments, resolve the path, and verify it remains under the intended memory directory."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/hygiene-checklist.md","line_end":3,"line_start":3},{"file":"references/hygiene-checklist.md","line_end":5,"line_start":5},{"file":"references/hygiene-checklist.md","line_end":35,"line_start":35},{"file":"references/hygiene-checklist.md","line_end":39,"line_start":39},{"file":"references/hygiene-checklist.md","line_end":51,"line_start":51},{"file":"references/hygiene-checklist.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":88,"line_start":88}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":36,"line_start":32},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":59},{"file":"SKILL.md","line_end":61,"line_start":60},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":78,"line_start":76},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":84,"line_start":79},{"file":"SKILL.md","line_end":85,"line_start":84},{"file":"SKILL.md","line_end":86,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]}],"critical_findings":[],"high_findings":[{"title":"Path traversal sequence","locations":[{"file":"SKILL.md","line_end":70,"line_start":70}],"confidence":0.87,"description":"After delivering, ask \"Save these results for future sessions?\" If yes, write the hygiene report + t","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"This line builds a write path with the user-derived <list-or-topic> placeholder and gives no sanitization or root-confinement rule. A traversal value could redirect the save outside the intended directory."}],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":52,"line_start":52}],"confidence":0.94,"description":"**Zero-dependency ESP read + measurement loop (when Resend is the ESP)**: `python3 \"${CLAUDE_PLUGIN_","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line explicitly directs execution of Python connector and ledger commands. The unquoted <list> placeholder can contain user-derived shell metacharacters and enable command injection."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":166,"audit_model":"codex","audited_at":"2026-07-10T11:13:45.235+00:00","created_at":"2026-07-11T00:02:30.792844+00:00","static_findings":[{"id":"filesystem:references/hygiene-checklist.md:3:path-traversal-sequence","file":"references/hygiene-checklist.md","pattern":"Path traversal sequence","snippet":"The watch behind `list-hygiene-monitor` — the recurring counterpart to the [deliverability-qa pre-fl","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/hygiene-checklist.md:5:path-traversal-sequence","file":"references/hygiene-checklist.md","pattern":"Path traversal sequence","snippet":"> Path note: this pack sits at `email/setup/list-hygiene-monitor/references/`, so repo root = `../..","category":"filesystem","line_end":5,"severity":"high","line_start":5},{"id":"filesystem:references/hygiene-checklist.md:35:path-traversal-sequence","file":"references/hygiene-checklist.md","pattern":"Path traversal sequence","snippet":"- A spam-complaint rate over the 0.1% red line, or any over-benchmark trend, means a **send-hold / a","category":"filesystem","line_end":35,"severity":"high","line_start":35},{"id":"filesystem:references/hygiene-checklist.md:39:path-traversal-sequence","file":"references/hygiene-checklist.md","pattern":"Path traversal sequence","snippet":"Read suppression-list growth over the window and check for leakage. The record itself belongs to [co","category":"filesystem","line_end":39,"severity":"high","line_start":39},{"id":"filesystem:references/hygiene-checklist.md:51:path-traversal-sequence","file":"references/hygiene-checklist.md","pattern":"Path traversal sequence","snippet":"| **Re-permission** (win-back) | dormant / deep-dormant, still deliverable, never complained | worth","category":"filesystem","line_end":51,"severity":"high","line_start":51},{"id":"filesystem:references/hygiene-checklist.md:76:path-traversal-sequence","file":"references/hygiene-checklist.md","pattern":"Path traversal sequence","snippet":"Report each cohort with a count (Measured/Estimated), the bounce/complaint trend vs baseline (or **N","category":"filesystem","line_end":76,"severity":"high","line_start":76},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The ongoing hygiene watch, not the pre-flight — a scheduled read of list decay and suppression drift","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":36,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: engagement-recency cohorts (30/90/180/365-day active → dormant), a hard-bounce ","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing hygiene report + the segmented re-permission / sunset / prune worklist p","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: hygiene blockers (bounce/complaint trending over benchmark, a dormant cohort large e","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Done when**: the list is cohorted by engagement recency with counts; hard-bounce and spam-compla","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `~~email platform` (ESP own-data manual export — the per-subscriber or cohort last-open/click en","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency ESP read + measurement loop (when Resend is the ESP)**: `python3 \"${CLAUDE_PLUGIN_","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Confirm scope, list, goal-weight column, and cadence** — name the program/list, whether it is p","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Cohort by engagement recency** — from the ESP engagement export, bucket subscribers by last-ope","category":"external_commands","line_end":60,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Trend bounce + complaint vs baseline** — compare the current hard-bounce rate and spam-complain","category":"external_commands","line_end":61,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Check suppression drift** — from [consent-registry](../../../protocol/consent-registry/SKILL.md","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Read SEND-`S` list-hygiene + SEND-`E` decay sub-items** — mark the `S` list-hygiene sub-item (b","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Scope guard**: this skill produces the recurring hygiene worklist and the **`S` list-hygiene + `E`","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"After delivering, ask \"Save these results for future sessions?\" If yes, write the hygiene report + t","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [send-benchmark.md](../../../references/send-benchmark.md) — SEND framework; the `S` list-hygiene ","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [deliverability-qa](../deliverability-qa/SKILL.md) — the sibling one-time auth pre-flight (`S1`); ","category":"external_commands","line_end":78,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [email-quality-auditor](../../deliver/email-quality-auditor/SKILL.md) — scores the full EQS and en","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — `~~email platform` own-data engagement + bounce/complain","category":"external_commands","line_end":84,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Primary**: [reactivation-specialist](../../nurture/reactivation-specialist/SKILL.md) — run the w","category":"external_commands","line_end":85,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **If the point-in-time send signal needs verifying before the next campaign**: [deliverability-qa]","category":"external_commands","line_end":86,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **If the hygiene reads are ready to roll into a verdict**: [email-quality-auditor](../../deliver/e","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.0\", \"discipline\": \"email\", \"phase\": \"setup\", \"","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:18:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"The ongoing hygiene watch, not the pre-flight — a scheduled read of list decay and suppression drift","category":"filesystem","line_end":18,"severity":"high","line_start":18},{"id":"filesystem:SKILL.md:38:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Reads**: the program/list + goal (promotional / retention / cold outbound, which sets the SEND w","category":"filesystem","line_end":38,"severity":"high","line_start":38},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [reactivation-specialist](../../nurture/reactivation-specialist/SKILL.md) ","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Use `~~email platform` (ESP own-data manual export — the per-subscriber or cohort last-open/click en","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Zero-dependency ESP read + measurement loop (when Resend is the ESP)**: `python3 \"${CLAUDE_PLUGIN_","category":"filesystem","line_end":52,"severity":"high","line_start":52},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat every exported file, subscriber list, and suppression dump as **untrusted** per [SECURITY.md](","category":"filesystem","line_end":56,"severity":"high","line_start":56},{"id":"filesystem:SKILL.md:58:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. **Confirm scope, list, goal-weight column, and cadence** — name the program/list, whether it is p","category":"filesystem","line_end":58,"severity":"high","line_start":58},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. **Check suppression drift** — from [consent-registry](../../../protocol/consent-registry/SKILL.md","category":"filesystem","line_end":61,"severity":"high","line_start":61},{"id":"filesystem:SKILL.md:66:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill produces the recurring hygiene worklist and the **`S` list-hygiene + `E`","category":"filesystem","line_end":66,"severity":"high","line_start":66},{"id":"filesystem:SKILL.md:70:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"After delivering, ask \"Save these results for future sessions?\" If yes, write the hygiene report + t","category":"filesystem","line_end":70,"severity":"high","line_start":70},{"id":"filesystem:SKILL.md:75:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [send-benchmark.md](../../../references/send-benchmark.md) — SEND framework; the `S` list-hygiene ","category":"filesystem","line_end":75,"severity":"high","line_start":75},{"id":"filesystem:SKILL.md:76:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [deliverability-qa](../deliverability-qa/SKILL.md) — the sibling one-time auth pre-flight (`S1`); ","category":"filesystem","line_end":76,"severity":"high","line_start":76},{"id":"filesystem:SKILL.md:77:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [consent-registry](../../../protocol/consent-registry/SKILL.md) — SSOT for the suppression / opt-o","category":"filesystem","line_end":77,"severity":"high","line_start":77},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [email-quality-auditor](../../deliver/email-quality-auditor/SKILL.md) — scores the full EQS and en","category":"filesystem","line_end":78,"severity":"high","line_start":78},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — `~~email platform` own-data engagement + bounce/complain","category":"filesystem","line_end":79,"severity":"high","line_start":79},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SECURITY.md](../../../SECURITY.md) — untrusted-data boundary for exported subscriber lists and su","category":"filesystem","line_end":80,"severity":"high","line_start":80},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [reactivation-specialist](../../nurture/reactivation-specialist/SKILL.md) — run the w","category":"filesystem","line_end":84,"severity":"high","line_start":84},{"id":"filesystem:SKILL.md:85:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the point-in-time send signal needs verifying before the next campaign**: [deliverability-qa]","category":"filesystem","line_end":85,"severity":"high","line_start":85},{"id":"filesystem:SKILL.md:86:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the hygiene reads are ready to roll into a verdict**: [email-quality-auditor](../../deliver/e","category":"filesystem","line_end":86,"severity":"high","line_start":86},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Termination**: follow the global rules in [skill-contract.md §Termination rules](../../../referenc","category":"filesystem","line_end":88,"severity":"high","line_start":88}],"finding_verdicts":[{"id":"filesystem:references/hygiene-checklist.md:3:path-traversal-sequence","reason":"The sequence occurs only in fixed Markdown links to repository documentation. It is not constructed from user input or used for a file operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/hygiene-checklist.md:5:path-traversal-sequence","reason":"This line documents repository-relative locations for readers. It performs no read or write and accepts no user-controlled path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/hygiene-checklist.md:35:path-traversal-sequence","reason":"The traversal sequence is part of a fixed Markdown link to another skill. No dynamic path construction or filesystem operation is present.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/hygiene-checklist.md:39:path-traversal-sequence","reason":"The sequence appears in a fixed documentation link to the consent registry. It is not used to access a user-selected file.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/hygiene-checklist.md:51:path-traversal-sequence","reason":"The sequence is only a repository-relative Markdown link for a handoff. It does not form an executable or user-controlled path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/hygiene-checklist.md:76:path-traversal-sequence","reason":"The traversal text occurs in fixed links to benchmark and auditor documentation. The line does not perform filesystem access.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"Backticks on this line format SEND labels in prose. They do not invoke Ruby, a shell, or any evaluator.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The backticks are a Markdown fence around an example user prompt. No command execution is requested.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"This is the closing Markdown fence for an example prompt. It has no shell or Ruby execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks open a plain Markdown example block. The enclosed text is a user request, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"This is a Markdown fence ending an example prompt. It does not execute or interpolate shell content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks delimit a documentation example. No interpreter or external command is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"This is the closing fence of a Markdown prompt example. It carries no execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Inline backticks format SEND field names and statuses. They do not denote shell substitution in Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticks format a local output directory and SEND labels. The line describes output, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"Inline backticks mark local filenames and labels in prose. No command is executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks format SEND status names. They are not shell execution syntax in this Markdown context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The backticks format connector labels and documentation terms. This line does not direct an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"This line explicitly directs execution of Python connector and ledger commands. The unquoted <list> placeholder can contain user-derived shell metacharacters and enable command injection.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Backticks format SEND labels and a documentation link. There is no external command on this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The detected characters are Markdown formatting for a SEND label. The line only describes cohorting logic.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"Inline backticks identify the S metric in prose. They do not execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The backticks format an N1 label while the path is a fixed Markdown link. No command execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"Backticks format SEND sub-item names. The line specifies reporting logic, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The detected backticks are inline formatting for metric names and veto labels. No shell evaluation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"Backticks format local paths and filenames. The line describes agent-managed file saving after consent, not shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"Inline backticks format SEND labels in a reference list. No external process is launched.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The detected backticks format an S1 label inside documentation. They have no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"Backticks format veto labels within a Markdown reference description. No command is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The backticks format a connector label in a fixed documentation link. The line does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The line is a Markdown link describing the next skill. No Ruby or shell command is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"Inline backticks only format an S1 label in a reference description. There is no external execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticks format audit labels in prose. The line contains no command invocation.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is package homepage metadata. It does not cause a runtime request or transmit user data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL appears in author metadata as a homepage. It is not an executable network operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:18:path-traversal-sequence","reason":"The traversal sequences are fixed Markdown links to sibling skills. They are not user-controlled or used in a file operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:38:path-traversal-sequence","reason":"The sequence appears in a fixed documentation link to the consent registry. No dynamic filesystem path is built.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","reason":"This is a fixed repository-relative Markdown link for a skill handoff. It does not accept user path input.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","reason":"The sequence is part of a fixed link to contract documentation. The line performs no file access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"The traversal text appears only in fixed links to repository documentation and skills. No user-controlled path is used.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:52:path-traversal-sequence","reason":"The traversal sequences occur in fixed Markdown links. The executable paths use a fixed plugin root and do not contain traversal components.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","reason":"The sequence is a fixed link to the repository security policy. It does not perform a filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:58:path-traversal-sequence","reason":"The traversal text is contained in a fixed benchmark-document link. No path is derived from user data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","reason":"The sequence appears in a fixed link to another skill. The line describes a logical check and does not access an arbitrary file.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:66:path-traversal-sequence","reason":"All traversal sequences on this line are fixed Markdown references. They are not dynamic paths or filesystem commands.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:70:path-traversal-sequence","reason":"This line builds a write path with the user-derived <list-or-topic> placeholder and gives no sanitization or root-confinement rule. A traversal value could redirect the save outside the intended directory.","verdict":"confirmed","severity":"high","confidence":0.87},{"id":"filesystem:SKILL.md:75:path-traversal-sequence","reason":"The sequence is part of a fixed Markdown link to benchmark documentation. No file operation or dynamic path is present.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:76:path-traversal-sequence","reason":"This is a fixed repository-relative link to a sibling skill. It is not a user-controlled traversal path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:77:path-traversal-sequence","reason":"The traversal sequence occurs only in a fixed link to the consent registry. No filesystem write or arbitrary read is directed.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","reason":"The sequence is a fixed Markdown link to the auditor skill. It is not formed from user input.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","reason":"The traversal text is a fixed documentation link. It does not authorize or perform arbitrary filesystem access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","reason":"The sequence is a fixed link to SECURITY.md. It performs no file operation and contains no user-derived component.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","reason":"This sequence occurs in a fixed link to the reactivation skill. It is not used as a dynamic path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:85:path-traversal-sequence","reason":"The path is a fixed Markdown reference to a sibling skill. No arbitrary read or write is requested.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:86:path-traversal-sequence","reason":"The traversal sequence is only a fixed link to the auditor skill. It is not user-controlled.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","reason":"The sequence is a fixed Markdown link to termination rules. The line performs no filesystem access.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}