{"data":{"skill":{"slug":"aaron-he-zhu-offer-claims-registry","name":"offer-claims-registry","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/protocol/offer-claims-registry","status":"approved","author":"aaron-he-zhu","authorVersion":"18.0.0","skillstoreRevision":1},"audit":{"id":"17bf17d9-4583-459b-83ae-476ddb941db0","skill_id":"16bd5b2f-86d9-487e-bd66-5dcdb82cf80c","version":8,"content_hash":"v3:635f69fb8d2f4e6330ba47a4e5a0fb239c04d110:40c4df9d43c61e2979432a69104aa5db0cebd14ae8555bbe7ac280ae27863ace:df59795142cb14d7037302f98ffcecc8cb8d05f2310154cf59017bf310b9a1c5:736b696c6c732f6161726f6e2d68652d7a68752f6f666665722d636c61696d732d7265676973747279:40594bec9f34933b67b6f36a81ca9d72","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 30 static findings are false positives caused by Markdown formatting, fixed documentation links, metadata URLs, and constrained repository commands. The skill requires explicit permission for registry writes and shows no prompt injection, exfiltration, or malicious intent.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":26,"line_start":22},{"file":"SKILL.md","line_end":30,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":43,"line_start":41},{"file":"SKILL.md","line_end":48,"line_start":43},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":51,"line_start":49},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":61,"line_start":57},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":48,"line_start":48}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":48,"line_start":48}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":142,"audit_model":"codex","audited_at":"2026-07-13T14:14:05.161+00:00","created_at":"2026-07-13T23:37:31.719935+00:00","static_findings":[{"id":"blocker:references/claims-ledger-schema.md:39:system-reconnaissance","file":"references/claims-ledger-schema.md","pattern":"System reconnaissance","snippet":"Ordinary skills do not write Markdown or NDJSON directly. With explicit permission, they pass a sche","category":"blocker","line_end":39,"severity":"low","line_start":39},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":26,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Units:** one claim or offer aggregate ID. **Reads:** `memory/events/claims.ndjson`, its projection","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All builders submit `propose`; only a host-capability `offer-claims-registry` principal accepts/reje","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- User-attested facts clearly labeled `user-provided`.","category":"external_commands","line_end":43,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Rendered ad/email/social/launch uses for `used_in` pointers.","category":"external_commands","line_end":48,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Read [`registry-event-protocol.md`](../../references/registry-event-protocol.md) and [`runtime-in","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Query `claims` projection by aggregate ID. Proposal state is never approved wording.","category":"external_commands","line_end":51,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Missing proof stays `none-on-file` in a proposal or open loop. Never turn `[needs source]` into A","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. Review pending proposal events in offset order. A host-capability principal invokes `owner-append","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. Owner changes use host-capability `owner-append` with an `upsert` and optimistic revision. Expiry","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"8. Regenerate `claims-ledger.md` / `offers.md` only from accepted projection state, then `verify cla","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Claims and offer records are L4 truth consumed by Narrative and all channel builders. A downstream b","category":"external_commands","line_end":61,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Require explicit write permission. Ordinary producers use `python3 \"$AARON_SKILLS_ROOT/scripts/regis","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:48:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"1. Read [`registry-event-protocol.md`](../../references/registry-event-protocol.md) and [`runtime-in","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:48:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"1. Read [`registry-event-protocol.md`](../../references/registry-event-protocol.md) and [`runtime-in","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"18.0.0\", \"discipline\": \"protocol\", \"phase\": \"protoc","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. Read [`registry-event-protocol.md`](../../references/registry-event-protocol.md) and [`runtime-in","category":"filesystem","line_end":48,"severity":"high","line_start":48},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Registry event protocol](../../references/registry-event-protocol.md)","category":"filesystem","line_end":65,"severity":"high","line_start":65},{"id":"filesystem:SKILL.md:67:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Measurement protocol](../../references/measurement-protocol.md)","category":"filesystem","line_end":67,"severity":"high","line_start":67},{"id":"filesystem:SKILL.md:68:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Security](../../SECURITY.md)","category":"filesystem","line_end":68,"severity":"high","line_start":68},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Paid use audit:** [ad-account-auditor](../../ad/activate/ad-account-auditor/SKILL.md)","category":"filesystem","line_end":72,"severity":"high","line_start":72},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Creator asset audit:** [creator-content-auditor](../../influencer/activate/creator-content-audit","category":"filesystem","line_end":73,"severity":"high","line_start":73},{"id":"filesystem:SKILL.md:74:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Narrative proof:** [proof-point-packager](../../narrative/land/proof-point-packager/SKILL.md)","category":"filesystem","line_end":74,"severity":"high","line_start":74},{"id":"filesystem:SKILL.md:75:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Archive/erase:** [memory-management](../memory-management/SKILL.md)","category":"filesystem","line_end":75,"severity":"high","line_start":75},{"id":"filesystem:SKILL.md:48:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"1. Read [`registry-event-protocol.md`](../../references/registry-event-protocol.md) and [`runtime-in","category":"filesystem","line_end":48,"severity":"low","line_start":48},{"id":"blocker:SKILL.md:12:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"argument-hint: \"<claim/offer aggregate-id or 'review pending proposals'>\"","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"blocker:SKILL.md:72:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Paid use audit:** [ad-account-auditor](../../ad/activate/ad-account-auditor/SKILL.md)","category":"blocker","line_end":72,"severity":"low","line_start":72}],"finding_verdicts":[{"id":"blocker:references/claims-ledger-schema.md:39:system-reconnaissance","reason":"The line defines how ordinary skills submit schema-valid registry requests with permission. It does not inspect the host system or collect system information.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The detected backticks open a fenced text example containing user prompts. No Ruby or shell expression is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The detected backticks close the fenced text example. They are Markdown delimiters and cannot execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"Backticks on this line format filenames and a script name in the skill contract. They do not provide shell execution semantics in Markdown.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backticks format operation and capability names. The prose restricts canonical writes to an authorized host principal.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks label evidence provenance as user-provided. This is Markdown formatting with no executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks format the used_in field name. No command or interpreter invocation appears on this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The backticks delimit Markdown links and inline shell text, not Ruby execution. The only command shown is a fixed Git repository-root lookup.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The line uses backticks to format the claims projection name. It contains no shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"Backticks format the none-on-file state. The line prevents unsupported evidence from being approved and contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Backticks format the owner-append operation name. The instruction limits this operation to a host-capability principal.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The marked terms are operation names formatted as inline code. The instruction also prohibits placing capability values in requests, files, or logs.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Backticks format generated filenames and a verification operation. No dynamic shell expression or untrusted argument is specified.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks format a needs-source marker in explanatory prose. They are not an execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The line documents a fixed local Python registry command and authorized operation names. It requires explicit write permission and does not interpolate user input into shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:48:shell-command-substitution","reason":"The substitution runs the hardcoded command git rev-parse to locate the repository root. It has no user-controlled command or argument and suppresses only diagnostic output.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:48:template-literal-with-command-substitution","reason":"The syntax is shell parameter expansion inside Markdown, not an executable JavaScript template literal. It selects a configured root or a fixed Git lookup.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is repository homepage metadata. The skill does not instruct the agent to send data to it or make a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL appears in OpenClaw metadata as the same public repository homepage. It is descriptive metadata, not a network operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:48:path-traversal-sequence","reason":"The parent segments are fixed Markdown links to protocol documents in the same repository. No user-controlled path can redirect access to an arbitrary file.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","reason":"This is a fixed relative Markdown link to the repository registry protocol. It is not used for a filesystem write or dynamic path resolution.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:67:path-traversal-sequence","reason":"This is a fixed relative Markdown link to the repository measurement protocol. No untrusted path component or file mutation is involved.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:68:path-traversal-sequence","reason":"This is a fixed relative Markdown link to the repository security document. It does not enable arbitrary traversal or modify a file.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:72:path-traversal-sequence","reason":"The parent segments form a fixed link to another bundled skill. No input controls the destination and no file operation is requested.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","reason":"The path is a static Markdown link to a related bundled skill. It cannot traverse to an attacker-selected location.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:74:path-traversal-sequence","reason":"The path is a static Markdown link to a related proof skill. It is documentation navigation rather than arbitrary filesystem access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:75:path-traversal-sequence","reason":"The single parent segment links to the adjacent memory-management skill. The fixed link contains no user-controlled path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:48:standard-device-file-access","reason":"The command redirects Git diagnostic output to the standard null device. It neither reads sensitive device data nor writes a persistent file.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:12:system-reconnaissance","reason":"This line is an argument hint for a claim identifier or proposal review request. It does not discover system details.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:72:system-reconnaissance","reason":"The line links to a related paid-use auditing skill. It contains no host enumeration, environment probing, or system information collection.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"635f69fb8d2f4e6330ba47a4e5a0fb239c04d110","subject_content_hash":"40c4df9d43c61e2979432a69104aa5db0cebd14ae8555bbe7ac280ae27863ace","subject_tree_hash":"df59795142cb14d7037302f98ffcecc8cb8d05f2310154cf59017bf310b9a1c5","subject_plugin_path":"skills/aaron-he-zhu/offer-claims-registry","audit_payload_hash":"40594bec9f34933b67b6f36a81ca9d72","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"635f69fb8d2f4e6330ba47a4e5a0fb239c04d110","contentHash":"40c4df9d43c61e2979432a69104aa5db0cebd14ae8555bbe7ac280ae27863ace","treeHash":"df59795142cb14d7037302f98ffcecc8cb8d05f2310154cf59017bf310b9a1c5","pluginPath":"skills/aaron-he-zhu/offer-claims-registry","auditPayloadHash":"40594bec9f34933b67b6f36a81ca9d72"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}