{"data":{"skill":{"slug":"aaron-he-zhu-offsite-signal-analyzer","name":"offsite-signal-analyzer","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/offsite-signal-analyzer","status":"approved","author":"aaron-he-zhu","authorVersion":"17.0.0","skillstoreRevision":1},"audit":{"id":"6eff8575-5576-4e5c-94dd-d5734b9f5596","skill_id":"28e62c4f-a524-47e1-afb4-783ae57cf84d","version":6,"content_hash":"v3:d71c7417a35d5c2624161bd2fe8de8a41a362128:397763daaaf5c71f67871550ef2805517b58fac134bc307f2b32df1cac9d5356:efe80472829eb1f2b8c81b802069bfd9f4b8116e287f000db184943fae947dae:736b696c6c732f6161726f6e2d68652d7a68752f6f6666736974652d7369676e616c2d616e616c797a6572:42ac060483c0773f4b8165a085acbe58","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Three command examples are confirmed medium-risk because they interpolate placeholders and invoke external Python scripts. The other 45 findings are documentation syntax, safe example domains, public links, or relative documentation references.","remediation":[{"issue":"Shell command examples interpolate user-controlled brands, queries, and domains.","severity":"medium","suggestion":"Use structured process arguments, validate each value, and avoid constructing shell command strings or pipelines."},{"issue":"The command examples invoke connector scripts outside this scanned skill package.","severity":"medium","suggestion":"Bundle auditable scripts with the skill or document their verified source, permissions, network behavior, and expected outputs."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/link-quality-rubric.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":75,"line_start":75}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":37,"line_start":32},{"file":"SKILL.md","line_end":39,"line_start":37},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":47,"line_start":46},{"file":"SKILL.md","line_end":48,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":52,"line_start":51},{"file":"SKILL.md","line_end":65,"line_start":52},{"file":"SKILL.md","line_end":67,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":81,"line_start":79},{"file":"SKILL.md","line_end":83,"line_start":81},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":129,"line_start":89},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":140,"line_start":136},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":152,"line_start":151},{"file":"SKILL.md","line_end":154,"line_start":152}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":113,"line_start":113},{"file":"SKILL.md","line_end":134,"line_start":134},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":147,"line_start":147},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":152,"line_start":152},{"file":"SKILL.md","line_end":154,"line_start":154}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.9,"description":"**Keyless unlinked-mention read (backlinks mode)**: `python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/connecto","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line explicitly directs execution of Python connector and ledger commands. Brand and domain placeholders may become user-controlled shell values without defined validation."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":73,"line_start":73}],"confidence":0.9,"description":"**Keyless upstream AI-citation spot-check (ai-referrals mode)**: referral logs only show clicks *aft","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line directs execution of Tavily and ledger Python commands using query and domain placeholders. Unsafe interpolation could permit command injection."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":83,"line_start":83}],"confidence":0.93,"description":"**Zero-dependency measurement loop (ai-referrals)**: store each period's AI-channel KPIs and let the","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line instructs execution of ledger.py with domain and data placeholders. An unquoted domain in a shell command creates a plausible injection path."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":525,"audit_model":"codex","audited_at":"2026-07-12T13:10:57.582+00:00","created_at":"2026-07-12T23:00:11.486745+00:00","static_findings":[{"id":"network:references/link-quality-rubric.md:103:hardcoded-url","file":"references/link-quality-rubric.md","pattern":"Hardcoded URL","snippet":"https://spam-site.example/toxic-page","category":"network","line_end":103,"severity":"low","line_start":103},{"id":"blocker:references/link-quality-rubric.md:74:system-reconnaissance","file":"references/link-quality-rubric.md","pattern":"System reconnaissance","snippet":"| Paid links you cannot get removed | Yes | Only after attempting removal |","category":"blocker","line_end":74,"severity":"low","line_start":74},{"id":"blocker:references/link-quality-rubric.md:100:system-reconnaissance","file":"references/link-quality-rubric.md","pattern":"System reconnaissance","snippet":"# Reason: [toxic link cleanup / negative SEO / paid links not removable]","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:references/outreach-templates.md:7:system-reconnaissance","file":"references/outreach-templates.md","pattern":"System reconnaissance","snippet":"| Rule | Do | Avoid |","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `backlinks` (default) | backlink-analyzer | `~~link database` export / pasted CSV | Referring doma","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ai-referrals` | ai-traffic | GA4 / GSC / server-log export | AI-assistant referral sessions, tren","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**The seam**: backlinks answers \"is this domain worth trusting as a source?\" from the link graph; ai","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":37,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":39,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If no mode is given, infer it: link/anchor/toxic/referring-domain wording → `backlinks`; AI-assistan","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: for `backlinks`, a backlink report (profile overview, quality/anchors/toxicity,","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks` — target domain, backlink/referring-domain exports, competitor domains, anchor data, a","category":"external_commands","line_end":47,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` — domain, date range, the user's GA4 export / Search Console data and/or server acc","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing monitoring deliverable and a reusable handoff summary under `memory/moni","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: significant changes, confirmed anomalies, new AI sources appearing, and follow-up ac","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks` — referring domains, anchor mix, and toxic-link share are reported with each metric so","category":"external_commands","line_end":52,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` — the AI source list is explicit, every figure is source-tagged, AI sessions and co","category":"external_commands","line_end":65,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All integrations optional and keyless on your own data (see [CONNECTORS.md](../../../CONNECTORS.md))","category":"external_commands","line_end":67,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**backlinks mode** — pull backlink profiles from `~~link database` and competitor data from `~~SEO t","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Keyless unlinked-mention read (backlinks mode)**: `python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/connecto","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**ai-referrals mode** — pull referral source/medium and conversions from `~~web analytics` (GA4 own ","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Keyless upstream AI-citation spot-check (ai-referrals mode)**: referral logs only show clicks *aft","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":81,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":83,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency measurement loop (ai-referrals)**: store each period's AI-channel KPIs and let the","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks` — no backlink data is provided and no `~~link database` is connected; link counts cann","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` — no GA4/GSC/log export is provided and no analytics tool is connected; AI sessions","category":"external_commands","line_end":129,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Pull AI-referral sessions** — in GA4 use an Exploration on `Session source / medium` filtered b","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**CITE item mapping** (ai-referrals): these figures are an **engagement signal that informs (does no","category":"external_commands","line_end":140,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Ask \"Save these results for future sessions?\" If yes, write to `memory/monitoring/` using filename `","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `backlinks`, toxic ratio > 15% or authority concern → [domain-authority-auditor](../domain-authori","category":"external_commands","line_end":152,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ai-referrals` → roll the AI channel into a full stakeholder report with [performance-monitor](../","category":"external_commands","line_end":154,"severity":"medium","line_start":152},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"17.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"network:SKILL.md:75:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Industry baseline for AI-crawler traffic (keyless)**: [Cloudflare Radar AI Insights](https://radar","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Reports the two off-site signal families a domain earns from the outside world: the **backlink profi","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:53:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [domain-authority-auditor](../domain-authority-auditor/SKILL.md) when toxi","category":"filesystem","line_end":53,"severity":"high","line_start":53},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":57,"severity":"high","line_start":57},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"This skill does **not**: score CITE or run vetoes (that is the [domain-authority-auditor](../domain-","category":"filesystem","line_end":61,"severity":"high","line_start":61},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"All integrations optional and keyless on your own data (see [CONNECTORS.md](../../../CONNECTORS.md))","category":"filesystem","line_end":65,"severity":"high","line_start":65},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Zero-dependency measurement loop (ai-referrals)**: store each period's AI-channel KPIs and let the","category":"filesystem","line_end":83,"severity":"high","line_start":83},{"id":"filesystem:SKILL.md:113:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**CITE item mapping** (what feeds [domain-authority-auditor](../domain-authority-auditor/SKILL.md) i","category":"filesystem","line_end":113,"severity":"high","line_start":113},{"id":"filesystem:SKILL.md:134:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"8. **Read movement against a control** — before crediting any change to an AI-traffic shift, apply [","category":"filesystem","line_end":134,"severity":"high","line_start":134},{"id":"filesystem:SKILL.md:140:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Ask \"Save these results for future sessions?\" If yes, write to `memory/monitoring/` using filename `","category":"filesystem","line_end":140,"severity":"high","line_start":140},{"id":"filesystem:SKILL.md:147:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Measurement & Attribution Protocol](../../../references/measurement-protocol.md) — readback windo","category":"filesystem","line_end":147,"severity":"high","line_start":147},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `backlinks`, toxic ratio > 15% or authority concern → [domain-authority-auditor](../domain-authori","category":"filesystem","line_end":151,"severity":"high","line_start":151},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- `ai-referrals` → roll the AI channel into a full stakeholder report with [performance-monitor](../","category":"filesystem","line_end":152,"severity":"high","line_start":152},{"id":"filesystem:SKILL.md:154:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Termination: visited-set check (if the target already ran in this chain, STOP and report chain-compl","category":"filesystem","line_end":154,"severity":"high","line_start":154}],"finding_verdicts":[{"id":"network:references/link-quality-rubric.md:103:hardcoded-url","reason":"The URL uses the reserved .example domain inside a disavow-file format example. It cannot direct traffic to an operational external service.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/link-quality-rubric.md:74:system-reconnaissance","reason":"This table row advises when paid links may warrant disavowal. It does not inspect the host system or request privileged information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/link-quality-rubric.md:100:system-reconnaissance","reason":"This is a comment template explaining why links were added to a disavow file. It contains no reconnaissance command or system access.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/outreach-templates.md:7:system-reconnaissance","reason":"The words form a Markdown table header for outreach guidance. They do not instruct system discovery or collect environment details.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Backticks format mode and connector labels in a Markdown table. No shell or Ruby expression is executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Backticks format the ai-referrals mode name in documentation. The line contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticked text names another skill for a documented handoff. It is not command substitution or executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"This line opens a fenced text block containing example user prompts. A Markdown fence does not execute its contents.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"This line closes a fenced text block. It has no command execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"Backticks identify two analysis modes in prose. The line only describes mode selection.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"Backticks format mode and output-path names in the skill contract. No external process is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The line documents inputs for backlinks mode. Its backticks are Markdown formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The line documents user-provided analytics inputs. It contains no command or execution primitive.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The backticked value is a relative output directory. The line describes a write contract, not external command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Backticks format memory filenames and a status value. No shell syntax or process invocation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The line states completion criteria for backlinks mode. Backticks only format the mode label.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The line states completion criteria for AI referral analysis. It does not invoke an external program.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The only backticked text is robots.txt within data-source guidance. The relative Markdown links are not commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticked phrases are abstract connector labels. They are not shell commands or Ruby expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The line explicitly directs execution of Python connector and ledger commands. Brand and domain placeholders may become user-controlled shell values without defined validation.","verdict":"confirmed","severity":"medium","confidence":0.9},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"Backticks denote optional analytics connector labels. The line requests exports when tools are unavailable and contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The line directs execution of Tavily and ledger Python commands using query and domain placeholders. Unsafe interpolation could permit command injection.","verdict":"confirmed","severity":"medium","confidence":0.9},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"This line opens a fenced block for a regular expression. It does not execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This line closes the regular-expression code fence. It has no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The line instructs execution of ledger.py with domain and data placeholders. An unquoted domain in a shell command creates a plausible injection path.","verdict":"confirmed","severity":"medium","confidence":0.93},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The line uses backticks to name a mode and an abstract connector. It defines a stop condition and executes nothing.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"Backticks format the ai-referrals mode name. The surrounding text requires user data or cancellation and contains no executable instruction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"Backticks format GA4 field and HTTP header names. The line describes filtering exported analytics or logs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The backticked name identifies a downstream skill. The line describes evidence boundaries and contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"Backticks format a relative directory, filename template, and skill name. The write occurs only after explicit user consent and is not external command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The backticked terms are a mode and downstream skill name. The line documents a recommendation rather than invoking a process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The backticked term names the ai-referrals mode. The Markdown link is a documented handoff, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:10:hardcoded-url","reason":"This URL is repository homepage metadata. It does not instruct a request or transmit user data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL repeats the public repository homepage in metadata. It is attribution, not an operational endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:75:hardcoded-url","reason":"The URL points to a public Cloudflare Radar benchmark and the text limits its use to industry context. No user data is sent.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","reason":"The traversal sequence is a relative Markdown link to shared CITE documentation. It does not read or write files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:53:path-traversal-sequence","reason":"The relative paths are Markdown links to neighboring skill documentation. They are not constructed from user input.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","reason":"The sequence navigates to a shared skill-contract document through a static Markdown link. No filesystem operation is directed.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:61:path-traversal-sequence","reason":"These are static relative links documenting scope and handoffs. No user-controlled path reaches a filesystem API.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","reason":"The sequences are static Markdown links to connector and security policies. They do not perform path traversal.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","reason":"The detected sequence appears in a static link to the connector README. The command risk on this line is adjudicated separately.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:113:path-traversal-sequence","reason":"This is a static relative Markdown link to a neighboring skill. It does not access a user-selected path.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:134:path-traversal-sequence","reason":"The relative sequence links to the shared measurement protocol. It is documentation navigation, not a filesystem read.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:140:path-traversal-sequence","reason":"The traversal sequence belongs to a static skill-contract link. The documented memory write uses a fixed local directory and asks for consent.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:147:path-traversal-sequence","reason":"The sequence is a static Markdown reference to the measurement protocol. It cannot escape a runtime path because no file API is used.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","reason":"The path is a static link to neighboring skill documentation. It is not combined with user-controlled data.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","reason":"The path is a static Markdown link used for a recommended handoff. It does not direct file access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:154:path-traversal-sequence","reason":"The relative path points to a fixed skill-contract document. The line describes workflow termination and contains no filesystem operation.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","subject_content_hash":"397763daaaf5c71f67871550ef2805517b58fac134bc307f2b32df1cac9d5356","subject_tree_hash":"efe80472829eb1f2b8c81b802069bfd9f4b8116e287f000db184943fae947dae","subject_plugin_path":"skills/aaron-he-zhu/offsite-signal-analyzer","audit_payload_hash":"42ac060483c0773f4b8165a085acbe58","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","contentHash":"397763daaaf5c71f67871550ef2805517b58fac134bc307f2b32df1cac9d5356","treeHash":"efe80472829eb1f2b8c81b802069bfd9f4b8116e287f000db184943fae947dae","pluginPath":"skills/aaron-he-zhu/offsite-signal-analyzer","auditPayloadHash":"42ac060483c0773f4b8165a085acbe58"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en","zh-hans"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}