{"data":{"skill":{"slug":"aaron-he-zhu-rank-tracker","name":"rank-tracker","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/seo-geo/monitor/rank-tracker","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"5e091ab6-7154-462a-9228-5ddbd16c86d1","skill_id":"2686bf97-37fc-433e-aa5e-58a968bf57a2","version":5,"content_hash":"v2:b9e5ae9c7a884b8b0bc6894c293164039a0aa79d:c7f0a240266e2e0f7c2cfa67354fb07116674b6b9652b6c1a8555a93fb437ec1:dc3e8ea06ce9716d243770994ec9492cae997d62774a4477c76ef9c687c30f44:debbad078dcddfb0dc9a814769ec32af","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Sixteen findings are false positives caused by Markdown fences, inline code, metadata URLs, and relative documentation links. The shell template on SKILL.md line 49 is confirmed because it executes an external Python script while leaving the domain placeholder unquoted, creating command-injection risk if substituted through a shell. No prompt injection or malicious data-exfiltration intent was found.","remediation":[{"issue":"The ledger command uses an unquoted domain placeholder and embeds variable data in a shell string.","severity":"medium","suggestion":"Use a structured argument array, validate domains and keywords, serialize data safely, and require confirmation before executing the external Python script."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":25,"line_start":23},{"file":"SKILL.md","line_end":27,"line_start":25},{"file":"SKILL.md","line_end":29,"line_start":27},{"file":"SKILL.md","line_end":33,"line_start":29},{"file":"SKILL.md","line_end":37,"line_start":33},{"file":"SKILL.md","line_end":49,"line_start":37},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":96,"line_start":54}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":14,"line_start":14}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":104,"line_start":104}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":49,"line_start":49}],"confidence":0.88,"description":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Line 49 instructs the agent to execute an external Python ledger script. The unquoted <domain> placeholder and embedded variable data could permit shell injection if substituted directly."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":359,"audit_model":"codex","audited_at":"2026-07-10T11:44:35.318+00:00","created_at":"2026-07-11T00:02:32.467857+00:00","static_findings":[{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":25,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":27,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":29,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":33,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Expected output**: a ranking report or delta summary plus the standard handoff summary for `memory","category":"external_commands","line_end":37,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: significant changes, confirmed anomalies, follow-up actions, and pending decisions t","category":"external_commands","line_end":49,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- No target keywords are provided and none can be inferred from `CLAUDE.md` or prior monitoring reco","category":"external_commands","line_end":96,"severity":"medium","line_start":54},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.0\", \"discipline\": \"seo-geo\", \"phase\": \"monitor","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"filesystem:SKILL.md:39:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [performance-monitor](../performance-monitor/SKILL.md) when recurring moni","category":"filesystem","line_end":39,"severity":"high","line_start":39},{"id":"filesystem:SKILL.md:43:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":43,"severity":"high","line_start":43},{"id":"filesystem:SKILL.md:47:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"All integrations optional (see [CONNECTORS.md](../../../CONNECTORS.md)). With tools, pull rankings f","category":"filesystem","line_end":47,"severity":"high","line_start":47},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","category":"filesystem","line_end":49,"severity":"high","line_start":49},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Ask \"Save these results?\" If yes, write to `memory/monitoring/` — see [Skill Contract](../../../refe","category":"filesystem","line_end":96,"severity":"high","line_start":96},{"id":"filesystem:SKILL.md:104:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Initial setup (no baseline) → [performance-monitor](../performance-monitor/SKILL.md). Subsequent run","category":"filesystem","line_end":104,"severity":"high","line_start":104},{"id":"blocker:SKILL.md:49:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Zero-dependency measurement loop** (no paid tool needed): never narrate a ranking movement you did","category":"blocker","line_end":49,"severity":"low","line_start":49}],"finding_verdicts":[{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"Line 23 is a Markdown code-fence delimiter. It does not execute Ruby, shell, or any other command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Line 25 closes a Markdown prompt example. The backticks are formatting syntax and contain no executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Line 27 opens a Markdown prompt example. It is documentation formatting, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"Line 29 closes a Markdown prompt example. No interpreter or command invocation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The backticks format the local path memory/monitoring/. They do not request command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backticks format the local file path memory/open-loops.md. This is not Ruby or shell syntax in context.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Line 49 instructs the agent to execute an external Python ledger script. The unquoted <domain> placeholder and embedded variable data could permit shell injection if substituted directly.","verdict":"confirmed","severity":"medium","confidence":0.88},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The matched range contains prose and inline Markdown references such as CLAUDE.md and local paths. It does not contain a Ruby backtick expression or a new executable command.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is the declared GitHub homepage in skill metadata. It does not initiate a request or transmit data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL is repeated as author homepage metadata. No network operation or external data transfer is instructed.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:39:path-traversal-sequence","reason":"The parent-directory sequence appears only in a relative Markdown link to another skill. It is not used for file access or traversal.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:43:path-traversal-sequence","reason":"The sequence is part of a relative documentation link. The text does not instruct reading or writing an arbitrary parent path.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:47:path-traversal-sequence","reason":"The parent-directory syntax is confined to a Markdown link for CONNECTORS.md. It is normal repository navigation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","reason":"The traversal sequences on line 49 occur in relative documentation links. The executable script path uses CLAUDE_PLUGIN_ROOT and does not contain parent-directory traversal.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:96:path-traversal-sequence","reason":"The parent-directory sequence is a Markdown link to the skill contract. The requested write targets memory/monitoring/ and requires explicit user approval.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:104:path-traversal-sequence","reason":"Both parent-directory sequences are relative Markdown links to repository documentation or another skill. They do not perform filesystem traversal.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:49:system-reconnaissance","reason":"Line 49 records and compares user-provided or connected ranking measurements. It does not enumerate system details, credentials, processes, or host configuration.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}