{"data":{"skill":{"slug":"aaron-he-zhu-performance-monitor","name":"performance-monitor","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/performance-monitor","status":"approved","author":"aaron-he-zhu","authorVersion":"17.0.0","skillstoreRevision":1},"audit":{"id":"b2803cca-2081-45eb-9e3c-9149db3a164f","skill_id":"1396854e-ba99-4ffa-a77c-f18e833f0bf6","version":6,"content_hash":"v3:d71c7417a35d5c2624161bd2fe8de8a41a362128:f95a3fcbad925ec13267195cf9c90a0385d8d2a1f542e18e8f5edfeac435aeb6:1e762e298787c3a15a753075886d7b78f9fc0bfd12faa1759dbf38be5b9e254a:736b696c6c732f6161726f6e2d68652d7a68752f706572666f726d616e63652d6d6f6e69746f72:54fc53d5990847ce23993b3d950da8bd","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most detections are Markdown syntax, documentation links, or metadata URLs without executable behavior. SKILL.md line 63 directs agents to run a Python ledger command with a domain argument. This creates command execution and input-handling risk, but no malicious or exfiltration intent was found.","remediation":[{"issue":"An executable ledger example accepts a domain placeholder as a command argument.","severity":"medium","suggestion":"Invoke ledger.py with an argument array, validate domain values, and require confirmation before recording data."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":36,"line_start":26},{"file":"SKILL.md","line_end":38,"line_start":36},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":46,"line_start":45},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":49,"line_start":48},{"file":"SKILL.md","line_end":54,"line_start":49},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":158,"line_start":157},{"file":"SKILL.md","line_end":160,"line_start":158}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":157,"line_start":157},{"file":"SKILL.md","line_end":160,"line_start":160}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":76,"line_start":76}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":63,"line_start":63}],"confidence":0.93,"description":"**Zero-dependency measurement loop** (both modes): every reported change or fired alert should come ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The line explicitly directs agents to run a Python ledger command. Its unquoted domain placeholder could become unsafe if passed through a shell."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":6,"total_lines":651,"audit_model":"codex","audited_at":"2026-07-12T13:27:49.209+00:00","created_at":"2026-07-12T23:00:12.535401+00:00","static_findings":[{"id":"blocker:references/kpi-definitions.md:13:system-reconnaissance","file":"references/kpi-definitions.md","pattern":"System reconnaissance","snippet":"| Organic search | Pages indexed | Valid indexed pages in Search Console | Close to intended indexab","category":"blocker","line_end":13,"severity":"low","line_start":13},{"id":"blocker:references/report-templates.md:76:system-reconnaissance","file":"references/report-templates.md","pattern":"System reconnaissance","snippet":"| Indexation | Valid indexed / excluded errors | [values] | [values] | [change] | [status] | [action","category":"blocker","line_end":76,"severity":"low","line_start":76},{"id":"blocker:references/report-templates.md:79:system-reconnaissance","file":"references/report-templates.md","pattern":"System reconnaissance","snippet":"| Schema | Valid / warning / error pages | [counts] | [counts] | [change] | [status] | [action] |","category":"blocker","line_end":79,"severity":"low","line_start":79},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"One monitor skill, two modes. **`report`** builds a stakeholder-facing multi-metric snapshot of what","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Mode set:** `report` (multi-metric snapshot, absorbed from performance-reporter) · `alert` (forwar","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":36,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Shortest valid invocation: `performance-monitor <domain>` (mode inferred). Output: **report** return","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: mode `report` → a delta-based multi-metric report/dashboard; mode `alert` → an ","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: prior baselines and current performance data. `report` reads current + prior-period met","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing monitoring deliverable plus a reusable summary storable under `memory/mo","category":"external_commands","line_end":46,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: significant changes, confirmed anomalies, durable thresholds, and follow-up actions;","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `report`: each in-scope section (traffic, rankings, GEO, authority, backlinks, content) is present","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `alert`: each chosen alert category has a named trigger, threshold, and priority; a Critical/High/","category":"external_commands","line_end":54,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency measurement loop** (both modes): every reported change or fired alert should come ","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Mode ambiguous** — the request fits neither past-tense (\"report on last month\") nor future-tense","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Step 0 — Select mode.** Read `--mode` if given. Otherwise infer: past-tense / \"how did we do\" / \"月","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Ask \"Save these results?\" If yes, write to `memory/monitoring/` using filename `YYYY-MM-DD-<topic>.m","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- After **report** — a change needs ongoing monitoring → run this skill in `alert` mode. A section m","category":"external_commands","line_end":158,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- After **alert** — a reporting cadence is requested → run this skill in `report` mode. Standalone a","category":"external_commands","line_end":160,"severity":"medium","line_start":158},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"17.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:22:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard — what this skill does NOT do:** it does not compute the CORE-EEAT content score or ru","category":"filesystem","line_end":22,"severity":"high","line_start":22},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":54,"severity":"high","line_start":54},{"id":"filesystem:SKILL.md:58:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"All integrations optional (see [CONNECTORS.md](../../../CONNECTORS.md)). Tier 1 (keyless) works for ","category":"filesystem","line_end":58,"severity":"high","line_start":58},{"id":"filesystem:SKILL.md:63:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Zero-dependency measurement loop** (both modes): every reported change or fired alert should come ","category":"filesystem","line_end":63,"severity":"high","line_start":63},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. **Keyword Rankings** — position ranges, distribution change, top improvements/declines, SERP feat","category":"filesystem","line_end":89,"severity":"high","line_start":89},{"id":"filesystem:SKILL.md:129:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"A reported delta or a fired alert is only evidence if it beats a control over a **fixed readback win","category":"filesystem","line_end":129,"severity":"high","line_start":129},{"id":"filesystem:SKILL.md:142:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Ask \"Save these results?\" If yes, write to `memory/monitoring/` using filename `YYYY-MM-DD-<topic>.m","category":"filesystem","line_end":142,"severity":"high","line_start":142},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Measurement & Attribution Protocol](../../../references/measurement-protocol.md) — readback windo","category":"filesystem","line_end":151,"severity":"high","line_start":151},{"id":"filesystem:SKILL.md:157:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- After **report** — a change needs ongoing monitoring → run this skill in `alert` mode. A section m","category":"filesystem","line_end":157,"severity":"high","line_start":157},{"id":"filesystem:SKILL.md:160:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Termination: the visited-set and `max-depth: 3` rules from [skill-contract.md §Termination rules](..","category":"filesystem","line_end":160,"severity":"high","line_start":160},{"id":"env_access:SKILL.md:76:configuration-library","file":"SKILL.md","pattern":"Configuration library","snippet":"- An alert category the user did not mention — leave it unconfigured; do not add alerts they did not","category":"env_access","line_end":76,"severity":"low","line_start":76},{"id":"blocker:SKILL.md:38:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Shortest valid invocation: `performance-monitor <domain>` (mode inferred). Output: **report** return","category":"blocker","line_end":38,"severity":"low","line_start":38},{"id":"blocker:SKILL.md:76:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- An alert category the user did not mention — leave it unconfigured; do not add alerts they did not","category":"blocker","line_end":76,"severity":"low","line_start":76},{"id":"blocker:SKILL.md:80:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Step 0 — Select mode.** Read `--mode` if given. Otherwise infer: past-tense / \"how did we do\" / \"月","category":"blocker","line_end":80,"severity":"low","line_start":80}],"finding_verdicts":[{"id":"blocker:references/kpi-definitions.md:13:system-reconnaissance","reason":"The line defines an SEO indexation KPI using Search Console. It does not inspect the host system or enumerate local resources.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/report-templates.md:76:system-reconnaissance","reason":"The line is a report placeholder for indexed and excluded page counts. It contains no system discovery instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/report-templates.md:79:system-reconnaissance","reason":"The line requests schema validation counts for an SEO report. It does not perform system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"Backticks format the report and alert mode names in prose. No Ruby or shell command is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"Backticks format two mode identifiers. The line describes behavior and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"This begins a fenced text block containing natural-language prompt examples. It contains no executable shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"This closes a Markdown text fence. It is formatting syntax, not backtick command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"Inline backticks document an invocation shape and storage path. The line does not instruct a shell to execute either string.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"Inline backticks identify output modes and a storage directory. They are documentation labels without command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The line uses inline code formatting for mode names while describing input data. It contains no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The backticked value is a scoped output directory described in prose. It is not shell substitution or an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Backticks format two Markdown filenames in a storage policy. The line does not execute them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The backticked report label is an inline mode name. The surrounding checklist contains no command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The backticked alert label is an inline mode name. The line only defines completion criteria.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The line contains inline mode labels and a Markdown link to documentation. Neither is an executable command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The line explicitly directs agents to run a Python ledger command. Its unquoted domain placeholder could become unsafe if passed through a shell.","verdict":"confirmed","severity":"medium","confidence":0.93},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"Backticks format report and alert option names in a decision prompt. No external process is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The line documents a mode option and mode values with inline code formatting. It does not execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"Backticks format a scoped directory and filename template. Writing occurs only after user confirmation, without shell substitution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The backticked alert value is a mode label. The line contains workflow links, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The backticked report value is a mode label. The line describes routing behavior without executing a process.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is repository homepage metadata. The skill does not request data from that URL.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL is repeated inside package metadata as a homepage. It is not a network destination used by the workflow.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:22:path-traversal-sequence","reason":"The parent-directory sequences are static Markdown links to related bundled skills. No user-controlled filesystem traversal occurs.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","reason":"The sequence appears in a Markdown link to a shared contract document. It is not used as a runtime file path.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:58:path-traversal-sequence","reason":"The sequence is a static relative link to connector documentation. It does not process user input or access arbitrary files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:63:path-traversal-sequence","reason":"Parent-directory sequences only link to bundled protocol and connector documentation. The executable example uses the plugin root variable instead.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","reason":"The sequence is a Markdown link to the related rank-tracker skill. It does not traverse a user-selected path.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:129:path-traversal-sequence","reason":"The sequence links to bundled measurement protocol documentation. It is static documentation navigation, not runtime traversal.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:142:path-traversal-sequence","reason":"The parent sequence belongs to a static documentation link. The proposed write is scoped to memory/monitoring and requires user approval.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:151:path-traversal-sequence","reason":"The sequence appears only in a Markdown reference to a bundled protocol file. No arbitrary file access is requested.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:157:path-traversal-sequence","reason":"The parent-directory paths are static links to two related skills. They do not incorporate user-controlled path components.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:160:path-traversal-sequence","reason":"The sequence is a Markdown link to shared termination rules. It is not used for filesystem traversal.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:76:configuration-library","reason":"The line discusses unrequested alert categories. It does not read environment variables or use a configuration library.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:38:system-reconnaissance","reason":"The line describes invocation and output formats for a user-supplied domain. It does not inspect the local system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:76:system-reconnaissance","reason":"The line limits configuration to categories requested by the user. It contains no system reconnaissance behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:80:system-reconnaissance","reason":"Reading the supplied mode option means parsing user arguments. It does not discover host configuration or system resources.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","subject_content_hash":"f95a3fcbad925ec13267195cf9c90a0385d8d2a1f542e18e8f5edfeac435aeb6","subject_tree_hash":"1e762e298787c3a15a753075886d7b78f9fc0bfd12faa1759dbf38be5b9e254a","subject_plugin_path":"skills/aaron-he-zhu/performance-monitor","audit_payload_hash":"54fc53d5990847ce23993b3d950da8bd","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"d71c7417a35d5c2624161bd2fe8de8a41a362128","contentHash":"f95a3fcbad925ec13267195cf9c90a0385d8d2a1f542e18e8f5edfeac435aeb6","treeHash":"1e762e298787c3a15a753075886d7b78f9fc0bfd12faa1759dbf38be5b9e254a","pluginPath":"skills/aaron-he-zhu/performance-monitor","auditPayloadHash":"54fc53d5990847ce23993b3d950da8bd"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en","zh-hans"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}