{"data":{"skill":{"slug":"aaron-he-zhu-reactivation-specialist","name":"reactivation-specialist","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/email/nurture/reactivation-specialist","status":"approved","author":"aaron-he-zhu","authorVersion":"19.0.0","skillstoreRevision":2},"audit":{"id":"b2f54891-8de1-4bad-bd63-9a5de49f03b6","skill_id":"ba517ce1-0a8d-4610-a86b-e74ede505064","version":6,"content_hash":"v3:0715a6e09ea875c8e28cb705ce87cc83045e69c1:abf815e3f195bc5f0941a5fb2acb25379c0847827159af83e74dc0096b34cdf2:9781cb8b9511388f280499740cc52a8181c5eedb744a04aef7dd7275f18884ea:736b696c6c732f6161726f6e2d68652d7a68752f726561637469766174696f6e2d7370656369616c697374:83fec03f64b02c0b0ef34c3a24469840","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are false positives from Markdown backticks and relative documentation links. One confirmed issue remains: the save instruction uses a user-derived cohort-or-goal placeholder without requiring filename sanitization or path containment. The skill otherwise instructs the agent to treat imported data as untrusted and requires user confirmation before saving.","remediation":[{"issue":"User-derived text can be placed in the save filename.","severity":"high","suggestion":"Sanitize cohort-or-goal to a fixed safe filename format, reject path separators and dot segments, and verify the resolved path remains under memory/email/reactivation-specialist before writing."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":26,"line_start":24},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":38,"line_start":32},{"file":"SKILL.md","line_end":39,"line_start":38},{"file":"SKILL.md","line_end":40,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":83,"line_start":73},{"file":"SKILL.md","line_end":83,"line_start":83}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":91,"line_start":91}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":73,"line_start":73}]}],"critical_findings":[],"high_findings":[{"title":"Path traversal sequence","locations":[{"file":"SKILL.md","line_end":73,"line_start":73}],"confidence":0.68,"description":"On user confirmation, save to `memory/email/reactivation-specialist/YYYY-MM-DD-<cohort-or-goal>.md` ","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The save path includes a cohort-or-goal placeholder that may be derived from user input. The instruction does not require filename validation or containment checks, so a host that follows it literally could write outside the intended directory."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":94,"audit_model":"claude","audited_at":"2026-07-27T11:41:51.529+00:00","created_at":"2026-07-28T01:15:52.005072+00:00","static_findings":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":24,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: the lapsed-cohort criteria (no-open / no-click window), the available incentive or offe","category":"external_commands","line_end":39,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a user-facing reactivation program (cohort + ladder + re-consent + sunset) and a reusa","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: the cohort window, offer-ladder steps, re-consent rule, sunset thresholds, and any m","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Tier 1 works from the user's own inputs: the lapsed-cohort criteria, the available incentive, and th","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Confirm the typed profile** — choose exactly one of `promotional`, `retention`, `cold-outbound`","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On user confirmation, save to `memory/email/reactivation-specialist/YYYY-MM-DD-<cohort-or-goal>.md` ","category":"external_commands","line_end":83,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~email platform`, `~~web an","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"19.0.0\", \"discipline\": \"email\", \"phase\": \"nurture\",","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:18:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Designs a closed-loop reactivation program for lapsed email cohorts — the win-back offer ladder, the","category":"filesystem","line_end":18,"severity":"high","line_start":18},{"id":"filesystem:SKILL.md:36:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Expected output**: a lapsed-cohort definition (the no-engagement window + how the cohort is pulled","category":"filesystem","line_end":36,"severity":"high","line_start":36},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [consent-registry](../../../protocol/consent-registry/SKILL.md) to record ","category":"filesystem","line_end":42,"severity":"high","line_start":42},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Tier 1 works from the user's own inputs: the lapsed-cohort criteria, the available incentive, and th","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Treat every exported or fetched file as untrusted input per [SECURITY.md](../../../SECURITY.md) — ne","category":"filesystem","line_end":54,"severity":"high","line_start":54},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. **Confirm the typed profile** — choose exactly one of `promotional`, `retention`, `cold-outbound`","category":"filesystem","line_end":56,"severity":"high","line_start":56},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"2. **Define the lapsed cohort** — state the no-engagement window (e.g., no open in 90 days, no click","category":"filesystem","line_end":57,"severity":"high","line_start":57},{"id":"filesystem:SKILL.md:59:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. **Add the re-consent / re-permission capture step** — a subject who re-engages must re-affirm opt","category":"filesystem","line_end":59,"severity":"high","line_start":59},{"id":"filesystem:SKILL.md:60:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"5. **Set the sunset-confirm rule** — the terminal branch after the last-chance step: a subject who r","category":"filesystem","line_end":60,"severity":"high","line_start":60},{"id":"filesystem:SKILL.md:62:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"7. **Hand the N-sub-item facts to their owners** — this program does **not** author any **N** sub-it","category":"filesystem","line_end":62,"severity":"high","line_start":62},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Scope guard**: this skill designs a **reactivation program only** — the lapsed cohort, offer ladde","category":"filesystem","line_end":64,"severity":"high","line_start":64},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On user confirmation, save to `memory/email/reactivation-specialist/YYYY-MM-DD-<cohort-or-goal>.md` ","category":"filesystem","line_end":73,"severity":"high","line_start":73},{"id":"filesystem:SKILL.md:77:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [send-benchmark.md](../../../references/send-benchmark.md) — SEND framework, the **N** engagement-","category":"filesystem","line_end":77,"severity":"high","line_start":77},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [skill-contract.md](../../../references/skill-contract.md) — shared contract, handoff schema, Outp","category":"filesystem","line_end":78,"severity":"high","line_start":78},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [consent-registry](../../../protocol/consent-registry/SKILL.md) — SSOT for consent / re-consent / ","category":"filesystem","line_end":79,"severity":"high","line_start":79},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [email-sequence-designer](../email-sequence-designer/SKILL.md) — the general lifecycle flows this ","category":"filesystem","line_end":80,"severity":"high","line_start":80},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [preference-frequency-manager](../preference-frequency-manager/SKILL.md) — owns and authors the pr","category":"filesystem","line_end":81,"severity":"high","line_start":81},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [list-segment-builder](../../setup/list-segment-builder/SKILL.md) — the lapsed / unengaged segment","category":"filesystem","line_end":82,"severity":"high","line_start":82},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — keyless export recipes for `~~email platform`, `~~web an","category":"filesystem","line_end":83,"severity":"high","line_start":83},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [SECURITY.md](../../../SECURITY.md) — treat every export as untrusted input.","category":"filesystem","line_end":84,"severity":"high","line_start":84},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary**: [consent-registry](../../../protocol/consent-registry/SKILL.md) — record the re-conse","category":"filesystem","line_end":88,"severity":"high","line_start":88},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the program is ready for the gate**: [email-quality-auditor](../../deliver/email-quality-audi","category":"filesystem","line_end":89,"severity":"high","line_start":89},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If re-permissioned subjects need the everyday flow to return to**: [email-sequence-designer](../","category":"filesystem","line_end":90,"severity":"high","line_start":90},{"id":"filesystem:SKILL.md:91:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **If the re-consent step needs a preference-center / opt-down ladder behind it**: [preference-freq","category":"filesystem","line_end":91,"severity":"high","line_start":91},{"id":"env_access:SKILL.md:73:configuration-library","file":"SKILL.md","pattern":"Configuration library","snippet":"On user confirmation, save to `memory/email/reactivation-specialist/YYYY-MM-DD-<cohort-or-goal>.md` ","category":"env_access","line_end":73,"severity":"low","line_start":73}],"finding_verdicts":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code formatting in prose and prompt examples, not executable Ruby or shell syntax. No command is invoked by this SKILL.md file.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:10:hardcoded-url","reason":"This is a metadata homepage URL, not a network request or instruction to send data. The skill contains no network operation.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:13:hardcoded-url","reason":"This is a metadata homepage URL, not a network request or instruction to send data. The skill contains no network operation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:18:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:36:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:42:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:46:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:54:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:56:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:59:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:60:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:62:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:64:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:73:path-traversal-sequence","reason":"The save path includes a cohort-or-goal placeholder that may be derived from user input. The instruction does not require filename validation or containment checks, so a host that follows it literally could write outside the intended directory.","verdict":"confirmed","severity":"high","confidence":0.68},{"id":"filesystem:SKILL.md:77:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:78:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:79:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:80:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:81:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:82:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:83:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:88:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:89:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:90:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:91:path-traversal-sequence","reason":"The detected sequence occurs in relative Markdown links to repository documentation or skills. These links are references, not file operations, and do not accept a traversal-controlled path.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:73:configuration-library","reason":"The line describes a local memory path and does not read environment variables or a configuration library. No environment access is present.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"0715a6e09ea875c8e28cb705ce87cc83045e69c1","subject_content_hash":"abf815e3f195bc5f0941a5fb2acb25379c0847827159af83e74dc0096b34cdf2","subject_tree_hash":"9781cb8b9511388f280499740cc52a8181c5eedb744a04aef7dd7275f18884ea","subject_plugin_path":"skills/aaron-he-zhu/reactivation-specialist","audit_payload_hash":"83fec03f64b02c0b0ef34c3a24469840","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"0715a6e09ea875c8e28cb705ce87cc83045e69c1","contentHash":"abf815e3f195bc5f0941a5fb2acb25379c0847827159af83e74dc0096b34cdf2","treeHash":"9781cb8b9511388f280499740cc52a8181c5eedb744a04aef7dd7275f18884ea","pluginPath":"skills/aaron-he-zhu/reactivation-specialist","auditPayloadHash":"83fec03f64b02c0b0ef34c3a24469840"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/aaron-he-zhu-reactivation-specialist/audits/6/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}