{"data":{"skill":{"slug":"aaron-he-zhu-offsite-signal-analyzer","name":"offsite-signal-analyzer","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/offsite-signal-analyzer","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"ffc1dd9d-3214-4a50-ae58-502777a0048b","skill_id":"28e62c4f-a524-47e1-afb4-783ae57cf84d","version":5,"content_hash":"v2:b9e5ae9c7a884b8b0bc6894c293164039a0aa79d:a4e03a0b0918b7011162e89c03d719810bfb00c21fdb4d52dddc6aa3b7a7edc4:43801281e1f96ad8291691c1b048b9fa7f670758b02271596734eecaee20ad48:131f8d2214e38c3d57669ae1dcb03d91","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Three findings are confirmed because SKILL.md directly recommends executing connector and ledger Python scripts with user-supplied placeholders. The other 45 detections are documentation syntax, example data, trusted informational links, or relative Markdown references; no prompt injection or malicious intent was found.","remediation":[{"issue":"Connector examples direct agents to execute local Python scripts with user-supplied query and domain values.","severity":"medium","suggestion":"Require user confirmation, validate all placeholders, and invoke scripts with structured arguments instead of interpolated shell commands."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/link-quality-rubric.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":75,"line_start":75}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":37,"line_start":32},{"file":"SKILL.md","line_end":39,"line_start":37},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":47,"line_start":46},{"file":"SKILL.md","line_end":48,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":52,"line_start":51},{"file":"SKILL.md","line_end":65,"line_start":52},{"file":"SKILL.md","line_end":67,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":81,"line_start":79},{"file":"SKILL.md","line_end":83,"line_start":81},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":129,"line_start":89},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":140,"line_start":136},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":152,"line_start":151},{"file":"SKILL.md","line_end":154,"line_start":152}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":113,"line_start":113},{"file":"SKILL.md","line_end":134,"line_start":134},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":147,"line_start":147},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":152,"line_start":152},{"file":"SKILL.md","line_end":154,"line_start":154}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.95,"description":"**Keyless unlinked-mention read (backlinks mode)**: `python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/connecto","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line directly instructs execution of Python connector and ledger scripts with brand and domain placeholders. Unvalidated interpolation can expose command and network risk."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":73,"line_start":73}],"confidence":0.95,"description":"**Keyless upstream AI-citation spot-check (ai-referrals mode)**: referral logs only show clicks *aft","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line directs execution of Tavily and ledger Python scripts using query and domain placeholders. These external operations require validation and consent."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":83,"line_start":83}],"confidence":0.94,"description":"**Zero-dependency measurement loop (ai-referrals)**: store each period's AI-channel KPIs and let the","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line explicitly runs ledger.py to record, compare, and trend user metrics. It performs local command execution and persistent data writes."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":525,"audit_model":"codex","audited_at":"2026-07-10T11:22:44.708+00:00","created_at":"2026-07-11T00:02:32.392914+00:00","static_findings":[{"id":"network:references/link-quality-rubric.md:103:hardcoded-url","file":"references/link-quality-rubric.md","pattern":"Hardcoded URL","snippet":"https://spam-site.example/toxic-page","category":"network","line_end":103,"severity":"low","line_start":103},{"id":"blocker:references/link-quality-rubric.md:74:system-reconnaissance","file":"references/link-quality-rubric.md","pattern":"System reconnaissance","snippet":"| Paid links you cannot get removed | Yes | Only after attempting removal |","category":"blocker","line_end":74,"severity":"low","line_start":74},{"id":"blocker:references/link-quality-rubric.md:100:system-reconnaissance","file":"references/link-quality-rubric.md","pattern":"System reconnaissance","snippet":"# Reason: [toxic link cleanup / negative SEO / paid links not removable]","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:references/outreach-templates.md:7:system-reconnaissance","file":"references/outreach-templates.md","pattern":"System reconnaissance","snippet":"| Rule | Do | Avoid |","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `backlinks` (default) | backlink-analyzer | `~~link database` export / pasted CSV | Referring doma","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ai-referrals` | ai-traffic | GA4 / GSC / server-log export | AI-assistant referral sessions, tren","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**The seam**: backlinks answers \"is this domain worth trusting as a source?\" from the link graph; ai","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":37,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":39,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If no mode is given, infer it: link/anchor/toxic/referring-domain wording → `backlinks`; AI-assistan","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: for `backlinks`, a backlink report (profile overview, quality/anchors/toxicity,","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks` — target domain, backlink/referring-domain exports, competitor domains, anchor data, a","category":"external_commands","line_end":47,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` — domain, date range, the user's GA4 export / Search Console data and/or server acc","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing monitoring deliverable and a reusable handoff summary under `memory/moni","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: significant changes, confirmed anomalies, new AI sources appearing, and follow-up ac","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks` — referring domains, anchor mix, and toxic-link share are reported with each metric so","category":"external_commands","line_end":52,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` — the AI source list is explicit, every figure is source-tagged, AI sessions and co","category":"external_commands","line_end":65,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All integrations optional and keyless on your own data (see [CONNECTORS.md](../../../CONNECTORS.md))","category":"external_commands","line_end":67,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**backlinks mode** — pull backlink profiles from `~~link database` and competitor data from `~~SEO t","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Keyless unlinked-mention read (backlinks mode)**: `python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/connecto","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**ai-referrals mode** — pull referral source/medium and conversions from `~~web analytics` (GA4 own ","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Keyless upstream AI-citation spot-check (ai-referrals mode)**: referral logs only show clicks *aft","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":81,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":83,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency measurement loop (ai-referrals)**: store each period's AI-channel KPIs and let the","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks` — no backlink data is provided and no `~~link database` is connected; link counts cann","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` — no GA4/GSC/log export is provided and no analytics tool is connected; AI sessions","category":"external_commands","line_end":129,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Pull AI-referral sessions** — in GA4 use an Exploration on `Session source / medium` filtered b","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**CITE item mapping** (ai-referrals): these figures are an **engagement signal that informs (does no","category":"external_commands","line_end":140,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Ask \"Save these results for future sessions?\" If yes, write to `memory/monitoring/` using filename `","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks`, toxic ratio > 15% or authority concern → [domain-authority-auditor](../domain-authori","category":"external_commands","line_end":152,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` → roll the AI channel into a full stakeholder report with [performance-monitor](../","category":"external_commands","line_end":154,"severity":"medium","line_start":152},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"network:SKILL.md:75:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Industry baseline for AI-crawler traffic (keyless)**: [Cloudflare Radar AI Insights](https://radar","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Reports the two off-site signal families a domain earns from the outside world: the **backlink profi","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:53:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [domain-authority-auditor](../domain-authority-auditor/SKILL.md) when toxi","category":"filesystem","line_end":53,"severity":"high","line_start":53},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":57,"severity":"high","line_start":57},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"This skill does **not**: score CITE or run vetoes (that is the [domain-authority-auditor](../domain-","category":"filesystem","line_end":61,"severity":"high","line_start":61},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"All integrations optional and keyless on your own data (see [CONNECTORS.md](../../../CONNECTORS.md))","category":"filesystem","line_end":65,"severity":"high","line_start":65},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Zero-dependency measurement loop (ai-referrals)**: store each period's AI-channel KPIs and let the","category":"filesystem","line_end":83,"severity":"high","line_start":83},{"id":"filesystem:SKILL.md:113:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**CITE item mapping** (what feeds [domain-authority-auditor](../domain-authority-auditor/SKILL.md) i","category":"filesystem","line_end":113,"severity":"high","line_start":113},{"id":"filesystem:SKILL.md:134:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"8. **Read movement against a control** — before crediting any change to an AI-traffic shift, apply [","category":"filesystem","line_end":134,"severity":"high","line_start":134},{"id":"filesystem:SKILL.md:140:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Ask \"Save these results for future sessions?\" If yes, write to `memory/monitoring/` using filename `","category":"filesystem","line_end":140,"severity":"high","line_start":140},{"id":"filesystem:SKILL.md:147:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Measurement & Attribution Protocol](../../../references/measurement-protocol.md) — readback windo","category":"filesystem","line_end":147,"severity":"high","line_start":147},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `backlinks`, toxic ratio > 15% or authority concern → [domain-authority-auditor](../domain-authori","category":"filesystem","line_end":151,"severity":"high","line_start":151},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `ai-referrals` → roll the AI channel into a full stakeholder report with [performance-monitor](../","category":"filesystem","line_end":152,"severity":"high","line_start":152},{"id":"filesystem:SKILL.md:154:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Termination: visited-set check (if the target already ran in this chain, STOP and report chain-compl","category":"filesystem","line_end":154,"severity":"high","line_start":154}],"finding_verdicts":[{"id":"network:references/link-quality-rubric.md:103:hardcoded-url","reason":"The URL uses the reserved .example domain inside a sample disavow file. It does not initiate a network request.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/link-quality-rubric.md:74:system-reconnaissance","reason":"This table row explains when paid links may warrant disavowal. It contains no system discovery or reconnaissance instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/link-quality-rubric.md:100:system-reconnaissance","reason":"This is a comment placeholder in a sample disavow file. It does not inspect or enumerate the host system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/outreach-templates.md:7:system-reconnaissance","reason":"The line is a Markdown table header for outreach guidance. It has no reconnaissance behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Inline code marks a mode name and connector placeholder. No executable command appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Inline code marks the ai-referrals mode in a documentation table. It is not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticks format a related skill name. The sentence describes data separation and contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"This line opens a text example block. A Markdown fence is not command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"This line closes a text example block. It has no executable content.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"Backticks format mode names used for request routing. No external process is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The line documents expected outputs and a storage path. It contains no shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The backticks identify the backlinks mode in a list of inputs. There is no command syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The backticks identify the ai-referrals mode in a list of inputs. There is no external execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The inline code is a relative storage directory. It is not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The code spans name memory files and a status value. They do not invoke external processes.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The line formats a mode label while defining completion criteria. It contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The line formats a mode label while defining reporting criteria. It contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The only inline code is robots.txt within a safety instruction. No process execution is requested.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The code spans are abstract connector placeholders, not shell commands or executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The line directly instructs execution of Python connector and ledger scripts with brand and domain placeholders. Unvalidated interpolation can expose command and network risk.","verdict":"confirmed","severity":"medium","confidence":0.95},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The code spans name optional analytics connectors. The line requests data sources but does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The line directs execution of Tavily and ledger Python scripts using query and domain placeholders. These external operations require validation and consent.","verdict":"confirmed","severity":"medium","confidence":0.95},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"This line opens a fenced regex example. It is not a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This line closes a fenced regex example. It has no executable behavior.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The line explicitly runs ledger.py to record, compare, and trend user metrics. It performs local command execution and persistent data writes.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"Inline code names a mode and optional connector. The line is a stop condition, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"Inline code names a mode and data sources. The line asks for user data and does not run a process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The code spans identify GA4 fields and an HTTP header. They are filter instructions, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The backticks format a related skill name. The line explains evidence limits and invokes no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The code spans describe a consent-gated storage path and filename. They are not external commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"Inline code labels a mode and links to a related skill. No process execution appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"Inline code labels a mode and links to a related skill. No command is executed.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:10:hardcoded-url","reason":"This is the project homepage in frontmatter metadata. It does not transmit data or trigger a request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL is repeated as project metadata. No request, credential use, or data transfer is present.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:75:hardcoded-url","reason":"The link points to Cloudflare Radar as a public industry benchmark. It is informational and does not include user data.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","reason":"The traversal sequence is inside a relative Markdown link to project documentation. It is not constructed from user input.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:53:path-traversal-sequence","reason":"The sequences are static sibling-skill Markdown links. They do not read or write arbitrary filesystem paths.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","reason":"This is a static relative link to the shared skill contract. No filesystem operation occurs.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","reason":"All traversal sequences are relative Markdown links to related skills. They are not user-controlled file paths.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","reason":"The sequence appears in static links to connector and security documentation. It does not access files dynamically.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","reason":"The traversal sequence belongs to a Markdown link to the connector README. The command itself uses a fixed plugin-root path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:113:path-traversal-sequence","reason":"This static relative link targets a sibling skill document. It is not a path traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:134:path-traversal-sequence","reason":"The sequence appears only in a relative link to measurement documentation. No file access is directed.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:140:path-traversal-sequence","reason":"The write target is the fixed memory/monitoring directory after user consent. No parent traversal sequence or arbitrary path is used.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:147:path-traversal-sequence","reason":"This is a static relative Markdown link to the measurement protocol. It does not perform filesystem traversal.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","reason":"The sequence is a sibling-skill Markdown link used for workflow routing. It is not a dynamic filesystem path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","reason":"The sequence is a sibling-skill Markdown link used for workflow routing. It does not access arbitrary files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:154:path-traversal-sequence","reason":"The sequence belongs to a static link to termination rules. The line defines workflow limits and performs no file access.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}