{"data":{"skill":{"slug":"aaron-he-zhu-rank-tracker","name":"rank-tracker","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/rank-tracker","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"99205c93-9fff-4527-a479-b0e891b04a41","skill_id":"2686bf97-37fc-433e-aa5e-58a968bf57a2","version":2,"content_hash":"41809d70eb833452b95575588f8af127","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are markdown formatting, metadata URLs, or documentation links rather than executable behavior. SKILL.md line 49 defines a real ledger command with user-controlled inputs. It should require explicit permission and safe argument handling; I found no prompt injection or exfiltration intent.","remediation":[{"issue":"External ledger command","severity":"medium","suggestion":"Document required command permissions, quote user-supplied arguments, and run ledger commands only after the user approves local execution."},{"issue":"Optional filesystem persistence","severity":"low","suggestion":"Keep result saving behind explicit user confirmation and write only within the declared memory/monitoring path."},{"issue":"Parent-directory documentation links","severity":"low","suggestion":"Replace parent-directory links with marketplace-safe relative links or inline summaries when the host cannot resolve repository paths."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":25,"line_start":23},{"file":"SKILL.md","line_end":27,"line_start":25},{"file":"SKILL.md","line_end":29,"line_start":27},{"file":"SKILL.md","line_end":33,"line_start":29},{"file":"SKILL.md","line_end":37,"line_start":33},{"file":"SKILL.md","line_end":49,"line_start":37},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":96,"line_start":54}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":14,"line_start":14}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":104,"line_start":104}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":49,"line_start":49}],"confidence":0.78,"description":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Line 49 instructs the agent to run python3 against a ledger.py script with user-provided domain and ranking data. The workflow appears legitimate, but it is real external command execution and should require permission and safe argument handling."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":359,"audit_model":"codex","audited_at":"2026-07-06T18:44:32.98+00:00","created_at":"2026-07-06T23:38:14.740672+00:00","static_findings":[{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":25,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":27,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":29,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":33,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: a ranking report or delta summary plus the standard handoff summary for `memory","category":"external_commands","line_end":37,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: significant changes, confirmed anomalies, follow-up actions, and pending decisions t","category":"external_commands","line_end":49,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- No target keywords are provided and none can be inferred from `CLAUDE.md` or prior monitoring reco","category":"external_commands","line_end":96,"severity":"medium","line_start":54},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"filesystem:SKILL.md:39:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [performance-monitor](../performance-monitor/SKILL.md) when recurring moni","category":"filesystem","line_end":39,"severity":"high","line_start":39},{"id":"filesystem:SKILL.md:43:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":43,"severity":"high","line_start":43},{"id":"filesystem:SKILL.md:47:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"All integrations optional (see [CONNECTORS.md](../../../CONNECTORS.md)). With tools, pull rankings f","category":"filesystem","line_end":47,"severity":"high","line_start":47},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","category":"filesystem","line_end":49,"severity":"high","line_start":49},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Ask \"Save these results?\" If yes, write to `memory/monitoring/` — see [Skill Contract](../../../refe","category":"filesystem","line_end":96,"severity":"high","line_start":96},{"id":"filesystem:SKILL.md:104:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Initial setup (no baseline) → [performance-monitor](../performance-monitor/SKILL.md). Subsequent run","category":"filesystem","line_end":104,"severity":"high","line_start":104},{"id":"blocker:SKILL.md:49:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","category":"blocker","line_end":49,"severity":"low","line_start":49}],"finding_verdicts":[{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"Lines 23-25 are a markdown prompt example inside a fenced code block. They do not invoke Ruby, shell backticks, or any executable command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Lines 25-27 only close and reopen markdown fences around examples. No command execution syntax is present beyond documentation formatting.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Lines 27-29 contain a natural-language example prompt in a markdown code fence. This is not shell or Ruby execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The finding spans markdown fence closure and nearby prose. There is no executable shell command or user-controlled backtick evaluation.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"Line 33 uses inline backticks to name the memory/monitoring path in documentation. It does not execute a command.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Lines 37-49 are mostly prose and documentation links. The backticks before line 49 are path formatting, not Ruby or shell execution.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Line 49 instructs the agent to run python3 against a ledger.py script with user-provided domain and ranking data. The workflow appears legitimate, but it is real external command execution and should require permission and safe argument handling.","verdict":"confirmed","severity":"medium","confidence":0.78},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Lines 54-96 describe decision gates, reporting rules, and a save prompt. The inline backticks are file and label formatting, not executable backtick evaluation.","verdict":"false_positive","confidence":0.89},{"id":"network:SKILL.md:10:hardcoded-url","reason":"Line 10 is a GitHub homepage URL in front matter metadata. It is not a network request, webhook, or data exfiltration endpoint.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:14:hardcoded-url","reason":"Line 14 embeds the same GitHub homepage in metadata for marketplace display. No runtime fetch or transmission is instructed there.","verdict":"false_positive","confidence":0.95},{"id":"filesystem:SKILL.md:39:path-traversal-sequence","reason":"Line 39 is a markdown link to a sibling skill using a parent-directory reference. It is documentation navigation, not file access or traversal.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:43:path-traversal-sequence","reason":"Line 43 links to a repository reference document with ../../../ notation. The text does not instruct reading arbitrary paths or escaping a sandbox.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:47:path-traversal-sequence","reason":"Line 47 uses a parent-directory markdown link to CONNECTORS.md. The line discusses optional integrations and does not perform path traversal.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","reason":"Line 49 contains repository-relative documentation links and a plugin-root script path, not ../ traversal against user input. The command aspect is covered by the external command verdict.","verdict":"false_positive","confidence":0.86},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","reason":"Line 96 tells the agent to save results only after asking the user and references a fixed memory/monitoring path. The ../../../ portion is a documentation link, not traversal of user-supplied paths.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:104:path-traversal-sequence","reason":"Line 104 links to adjacent repository documentation and another skill. It does not instruct filesystem reads or writes outside a fixed workflow.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:49:system-reconnaissance","reason":"Line 49 is a domain rank-tracking ledger workflow. It does not enumerate local users, processes, environment details, network interfaces, or other host reconnaissance data.","verdict":"false_positive","confidence":0.9}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}