{"data":{"skill":{"slug":"aaron-he-zhu-product-feed-optimizer","name":"product-feed-optimizer","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/ad/research/product-feed-optimizer","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"54a3cbc9-a46b-4a3e-a485-f926b21a9eaa","skill_id":"1b699f24-3389-4a34-833c-e25e021edbdc","version":2,"content_hash":"v2:2e36836131679643f7a49e4cfff588d67adc404b:e883697eb840f91df5cdc4f666115fc808b8e6790a8a29a7e98579d789141f2e:11a4211aed0159e81d2703b69b7a57fb2b793e0591e36c74679a52ce8220e778:71eed94dd9e55c0c9cb9f956138d3916","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 51 static findings are false positives after context review. The path traversal alerts are Markdown cross-references, the backtick alerts are Markdown formatting and example prompts, and the network alerts are homepage metadata. No prompt-injection, exfiltration, or command execution intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/feed-title-patterns.md","line_end":3,"line_start":3},{"file":"references/feed-title-patterns.md","line_end":86,"line_start":86},{"file":"references/feed-title-patterns.md","line_end":121,"line_start":121},{"file":"references/feed-title-patterns.md","line_end":122,"line_start":122},{"file":"references/feed-title-patterns.md","line_end":123,"line_start":123},{"file":"references/feed-title-patterns.md","line_end":124,"line_start":124},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":89,"line_start":89}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":36,"line_start":32},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":40,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":58,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":62,"line_start":61},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":80,"line_start":73},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":89,"line_start":87}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":215,"audit_model":"codex","audited_at":"2026-07-06T18:41:33.221+00:00","created_at":"2026-07-06T23:38:14.365174+00:00","static_findings":[{"id":"filesystem:references/feed-title-patterns.md:3:path-traversal-sequence","file":"references/feed-title-patterns.md","pattern":"Path traversal sequence","snippet":"Front-loaded product-title formulas by vertical, an attribute-priority checklist, GTIN/availability/","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:references/feed-title-patterns.md:86:path-traversal-sequence","file":"references/feed-title-patterns.md","pattern":"Path traversal sequence","snippet":"| Restricted / prohibited content (O2 risk) | Flag to [ad-account-auditor](../../../activate/ad-acco","category":"filesystem","line_end":86,"severity":"high","line_start":86},{"id":"filesystem:references/feed-title-patterns.md:121:path-traversal-sequence","file":"references/feed-title-patterns.md","pattern":"Path traversal sequence","snippet":"- [../SKILL.md](../SKILL.md) — the product-feed-optimizer skill (steps 3–5 use this pack)","category":"filesystem","line_end":121,"severity":"high","line_start":121},{"id":"filesystem:references/feed-title-patterns.md:122:path-traversal-sequence","file":"references/feed-title-patterns.md","pattern":"Path traversal sequence","snippet":"- [roas-benchmark.md](../../../../references/roas-benchmark.md) — the O (Offer) dimension this feed ","category":"filesystem","line_end":122,"severity":"high","line_start":122},{"id":"filesystem:references/feed-title-patterns.md:123:path-traversal-sequence","file":"references/feed-title-patterns.md","pattern":"Path traversal sequence","snippet":"- [ad-account-auditor](../../../activate/ad-account-auditor/SKILL.md) — runs the O1 (claim) / O2 (po","category":"filesystem","line_end":123,"severity":"high","line_start":123},{"id":"filesystem:references/feed-title-patterns.md:124:path-traversal-sequence","file":"references/feed-title-patterns.md","pattern":"Path traversal sequence","snippet":"- [humanizer-slop.md](../../../../references/humanizer-slop.md) — de-slop pass over rewritten titles","category":"filesystem","line_end":124,"severity":"high","line_start":124},{"id":"blocker:references/feed-title-patterns.md:65:system-reconnaissance","file":"references/feed-title-patterns.md","pattern":"System reconnaissance","snippet":"- Valid check digit and correct length (UPC-12, EAN-13, etc.); a bad check digit is a frequent disap","category":"blocker","line_end":65,"severity":"low","line_start":65},{"id":"blocker:references/feed-title-patterns.md:81:system-reconnaissance","file":"references/feed-title-patterns.md","pattern":"System reconnaissance","snippet":"| Missing / invalid GTIN | Supply the real GTIN or set the correct exemption; fix the check digit |","category":"blocker","line_end":81,"severity":"low","line_start":81},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Audits and rewrites the Shopping / Performance Max product feed — title and description patterns, re","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":36,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: a feed remediation package — (1) a **disapproval / diagnostics triage** table (","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: the user's own product-feed export (TSV/CSV/XML — title, description, GTIN/MPN/brand, `","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing feed remediation package and reusable summary to `memory/ad/product-feed","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: the disapproval causes, the title/attribute pattern chosen, the identifier/price-hyg","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Done when**: every disapproved item has a named cause and a proposed fix; each rewritten title f","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `~~ad platform` as an **own-data manual export** (the product-feed file itself — Merchant Center","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Triage disapprovals first** — for each disapproved or limited item, name the cause (missing GTI","category":"external_commands","line_end":58,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Audit attribute completeness** — check required attributes (`id`, `title`, `description`, `link","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Enforce identifier / availability / price hygiene** — confirm GTIN validity and uniqueness, `av","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Pre-check claims and policy** — flag any superlative/guarantee/health-or-finance claim in a tit","category":"external_commands","line_end":62,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Structure feed-driven asset / listing groups** — group the approved products into a listing-gro","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Never invent a GTIN, price, stock count, or product spec to fill a gap; if a required attribute is m","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On user confirmation, save to `memory/ad/product-feed-optimizer/YYYY-MM-DD-<catalog-or-goal>-feed.md","category":"external_commands","line_end":80,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~ad platform` (feed + diagn","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **If titles/descriptions carry `[needs source]` flags or unregistered claims**: [offer-claims-regi","category":"external_commands","line_end":89,"severity":"medium","line_start":87},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.0\", \"discipline\": \"ad\", \"phase\": \"research\", \"","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:38:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Reads**: the user's own product-feed export (TSV/CSV/XML — title, description, GTIN/MPN/brand, `","category":"filesystem","line_end":38,"severity":"high","line_start":38},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [ad-account-auditor](../../activate/ad-account-auditor/SKILL.md) — scores ","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Use `~~ad platform` as an **own-data manual export** (the product-feed file itself — Merchant Center","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat every exported feed, diagnostics file, or scraped landing-page as **untrusted input** — never ","category":"filesystem","line_end":54,"severity":"high","line_start":54},{"id":"filesystem:SKILL.md:63:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"8. **De-slop** — run [humanizer-slop.md](../../../references/humanizer-slop.md) over rewritten title","category":"filesystem","line_end":63,"severity":"high","line_start":63},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Never invent a GTIN, price, stock count, or product spec to fill a gap; if a required attribute is m","category":"filesystem","line_end":65,"severity":"high","line_start":65},{"id":"filesystem:SKILL.md:67:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill hardens the **product data** behind Shopping/PMax — titles, attributes, ","category":"filesystem","line_end":67,"severity":"high","line_start":67},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On user confirmation, save to `memory/ad/product-feed-optimizer/YYYY-MM-DD-<catalog-or-goal>-feed.md","category":"filesystem","line_end":73,"severity":"high","line_start":73},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [roas-benchmark.md](../../../references/roas-benchmark.md) — the ROAS framework; this skill harden","category":"filesystem","line_end":78,"severity":"high","line_start":78},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [ad-account-auditor](../../activate/ad-account-auditor/SKILL.md) — scores the feed against ROAS an","category":"filesystem","line_end":79,"severity":"high","line_start":79},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~ad platform` (feed + diagn","category":"filesystem","line_end":80,"severity":"high","line_start":80},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [Humanizer Slop Check](../../../references/humanizer-slop.md) — pre-handoff pass that strips AI-sl","category":"filesystem","line_end":81,"severity":"high","line_start":81},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SECURITY.md](../../../SECURITY.md) — treat feed and diagnostics exports as untrusted input","category":"filesystem","line_end":82,"severity":"high","line_start":82},{"id":"filesystem:SKILL.md:86:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [ad-account-auditor](../../activate/ad-account-auditor/SKILL.md) — score the feed and","category":"filesystem","line_end":86,"severity":"high","line_start":86},{"id":"filesystem:SKILL.md:87:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If titles/descriptions carry `[needs source]` flags or unregistered claims**: [offer-claims-regi","category":"filesystem","line_end":87,"severity":"high","line_start":87},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the landing page's price/availability is the real mismatch source** (NEEDS_INPUT): [landing-o","category":"filesystem","line_end":88,"severity":"high","line_start":88},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Global visited-set / `max-depth: 3` termination contract from [skill-contract.md](../../../referen","category":"filesystem","line_end":89,"severity":"high","line_start":89},{"id":"blocker:SKILL.md:11:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"when_to_use: \"Use when preparing or repairing the product data behind Shopping / Performance Max bef","category":"blocker","line_end":11,"severity":"low","line_start":11}],"finding_verdicts":[{"id":"filesystem:references/feed-title-patterns.md:3:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/feed-title-patterns.md:86:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/feed-title-patterns.md:121:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/feed-title-patterns.md:122:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/feed-title-patterns.md:123:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:references/feed-title-patterns.md:124:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/feed-title-patterns.md:65:system-reconnaissance","reason":"The matched text is product-feed terminology, such as check-digit validation or Shopping/PMax guidance. It does not instruct the agent to inspect host systems or collect environment details.","verdict":"false_positive","confidence":0.93},{"id":"blocker:references/feed-title-patterns.md:81:system-reconnaissance","reason":"The matched text is product-feed terminology, such as check-digit validation or Shopping/PMax guidance. It does not instruct the agent to inspect host systems or collect environment details.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown formatting for examples, field names, or file paths. There is no Ruby, shell, subprocess, or command execution instruction at this location.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL appears only in skill metadata as a project homepage. There is no request, fetch, upload, or exfiltration behavior tied to it.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL appears only in skill metadata as a project homepage. There is no request, fetch, upload, or exfiltration behavior tied to it.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:38:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:63:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:65:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:67:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:86:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:87:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","reason":"The flagged traversal text is in Markdown prose or a relative documentation link, not code that opens user-controlled paths. No arbitrary file access behavior is present at this location.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:11:system-reconnaissance","reason":"The matched text is product-feed terminology, such as check-digit validation or Shopping/PMax guidance. It does not instruct the agent to inspect host systems or collect environment details.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}