{"data":{"skill":{"slug":"aaron-he-zhu-report-generator","name":"report-generator","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/influencer/measure/report-generator","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"b1efeec1-4dd8-4dba-bb63-6d9e30cf68fe","skill_id":"c70c9c68-6575-4c7d-be54-314f548fb7f2","version":3,"content_hash":"v2:7ed2830f0283f3a8900137d8dc893e54072206f3:5be473ecd68c30c069b83778b0f2a6fa8311d958934306ffd172d6b45d67a54e:2cb022f9931cf8bcfe1faa37f28415259de45e7ceea2c859098601d80c78a97c:ffb956b506c2e9ad883fd02b860ca5b1","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"No confirmed malicious behavior was found in the reviewed files. Static findings are explained by Markdown code fences, inline formatting, source metadata URLs, relative documentation links, and fixed memory output paths.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/report-templates.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":112,"line_start":112},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":121,"line_start":121}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":32,"line_start":28},{"file":"SKILL.md","line_end":34,"line_start":32},{"file":"SKILL.md","line_end":38,"line_start":34},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":40,"line_start":39},{"file":"SKILL.md","line_end":57,"line_start":40},{"file":"SKILL.md","line_end":58,"line_start":57},{"file":"SKILL.md","line_end":59,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":59},{"file":"SKILL.md","line_end":70,"line_start":60},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":100,"line_start":84}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":637,"audit_model":"codex","audited_at":"2026-07-07T06:37:24.418+00:00","created_at":"2026-07-07T08:33:07.034895+00:00","static_findings":[{"id":"filesystem:references/report-templates.md:3:path-traversal-sequence","file":"references/report-templates.md","pattern":"Path traversal sequence","snippet":"Full audience templates, visualization recommendations, writing best practices, and a worked example","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"blocker:references/report-templates.md:19:system-reconnaissance","file":"references/report-templates.md","pattern":"System reconnaissance","snippet":"| Client | Results, Value | Medium | \"What did I get?\" |","category":"blocker","line_end":19,"severity":"low","line_start":19},{"id":"blocker:references/report-templates.md:457:system-reconnaissance","file":"references/report-templates.md","pattern":"System reconnaissance","snippet":"2. **Execution**: What we did","category":"blocker","line_end":458,"severity":"low","line_start":457},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **Cross-discipline (paid ads):** this is also the **paid-ads** reporting surface — build exec/clie","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":34,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: campaign name, reporting period, target audience, and computed metrics (reach, engageme","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: a finished report in the audience-appropriate template, saved to `memory/influencer/re","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: durable verdicts (final ROI/ROAS, top performers, renew/drop calls, headline learnin","category":"external_commands","line_end":57,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~social platform analytics` — reach, impressions, engagement, video views per post","category":"external_commands","line_end":58,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~influencer database` — creator handles, tiers, fees, audience demographics","category":"external_commands","line_end":59,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~analytics` — link clicks, conversions, attributed revenue","category":"external_commands","line_end":60,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~CRM` — new-customer counts and downstream revenue","category":"external_commands","line_end":70,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Pick the audience template and fill it in** — full executive, client, and internal-team templat","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Save and promote** — write the finished report to `memory/influencer/report-generator/YYYY-MM-D","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":100,"severity":"medium","line_start":84},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.1\", \"discipline\": \"influencer\", \"phase\": \"meas","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> **Cross-discipline (paid ads):** this is also the **paid-ads** reporting surface — build exec/clie","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:SKILL.md:45:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [content-quality-auditor](../../../seo-geo/optimize/content-quality-audito","category":"filesystem","line_end":45,"severity":"high","line_start":45},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":49,"severity":"high","line_start":49},{"id":"filesystem:SKILL.md:62:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Without any of these, the skill asks you for the numbers and proceeds. See [CONNECTORS.md](../../../","category":"filesystem","line_end":62,"severity":"high","line_start":62},{"id":"filesystem:SKILL.md:105:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [skill-contract.md](../../../references/skill-contract.md) — shared contract and handoff format","category":"filesystem","line_end":105,"severity":"high","line_start":105},{"id":"filesystem:SKILL.md:106:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [state-model.md](../../../references/state-model.md) — memory tiers and save-path convention","category":"filesystem","line_end":106,"severity":"high","line_start":106},{"id":"filesystem:SKILL.md:107:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — free/keyless data recipes per connector category","category":"filesystem","line_end":107,"severity":"high","line_start":107},{"id":"filesystem:SKILL.md:108:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [performance-analyzer](../performance-analyzer/SKILL.md) — generates the metrics this report consu","category":"filesystem","line_end":108,"severity":"high","line_start":108},{"id":"filesystem:SKILL.md:109:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [roi-calculator](../roi-calculator/SKILL.md) — supplies ROI/ROAS figures","category":"filesystem","line_end":109,"severity":"high","line_start":109},{"id":"filesystem:SKILL.md:110:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [campaign-planner](../../plan/campaign-planner/SKILL.md) — original plan to compare results agains","category":"filesystem","line_end":110,"severity":"high","line_start":110},{"id":"filesystem:SKILL.md:111:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [content-amplifier](../../activate/content-amplifier/SKILL.md) — amplification results to report o","category":"filesystem","line_end":111,"severity":"high","line_start":111},{"id":"filesystem:SKILL.md:112:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [content-quality-auditor](../../../seo-geo/optimize/content-quality-auditor/SKILL.md) — quality ga","category":"filesystem","line_end":112,"severity":"high","line_start":112},{"id":"filesystem:SKILL.md:116:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Primary**: [content-quality-auditor](../../../seo-geo/optimize/content-quality-auditor/SKILL.md) —","category":"filesystem","line_end":116,"severity":"high","line_start":116},{"id":"filesystem:SKILL.md:120:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [performance-analyzer](../performance-analyzer/SKILL.md) — if the report exposes data gaps, re-ana","category":"filesystem","line_end":120,"severity":"high","line_start":120},{"id":"filesystem:SKILL.md:121:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [roi-calculator](../roi-calculator/SKILL.md) — recompute return figures if the financial inputs ch","category":"filesystem","line_end":121,"severity":"high","line_start":121},{"id":"blocker:SKILL.md:20:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"> **Cross-discipline (paid ads):** this is also the **paid-ads** reporting surface — build exec/clie","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:SKILL.md:76:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"5. **Save and promote** — write the finished report to `memory/influencer/report-generator/YYYY-MM-D","category":"blocker","line_end":76,"severity":"low","line_start":76},{"id":"blocker:SKILL.md:123:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Termination note** (visited-set): if a recommended skill has already been invoked this session, st","category":"blocker","line_end":123,"severity":"low","line_start":123}],"finding_verdicts":[{"id":"filesystem:references/report-templates.md:3:path-traversal-sequence","reason":"The parent-directory token appears in a Markdown link to the local SKILL.md file. It is documentation navigation, not arbitrary filesystem access.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/report-templates.md:19:system-reconnaissance","reason":"The phrase is part of an audience-needs table for client reporting. It does not ask the agent to inspect the host system or enumerate files.","verdict":"false_positive","confidence":0.93},{"id":"blocker:references/report-templates.md:457:system-reconnaissance","reason":"This line is a narrative report structure step, \"Execution: What we did\". It is about campaign activity, not system reconnaissance.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The backticks mark inline paths and a Markdown link in prose about report inputs. There is no shell command, Ruby execution, or command interpolation.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"This is the opening fence for a Markdown example prompt. It is not executable code and contains no command invocation.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"This is the closing fence for a Markdown example prompt. It is not Ruby backtick execution or shell syntax.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"This is the opening fence for another Markdown example prompt. The fenced text is a user request example, not a command.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This is the closing fence for the example prompt block. There is no executable shell or Ruby context.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The backticks identify related skill names in documentation. They do not execute commands or pass user input to a shell.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticks format an intended report output path under memory. This is a documentation path, not shell execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The backticks format the memory file name used for promoted summaries. This line does not invoke an external command.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks format an optional connector label. The line is a data source description, not command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks format an optional connector label. It does not contain shell syntax or executable code.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The backticks format an optional analytics connector label. It is not a command invocation.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The backticks format an optional CRM connector label. There is no execution context or command string.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks identify related skill names used as metric sources. They are inline Markdown formatting, not shell execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The backticks format fixed memory output paths. The line instructs saving generated reports, not running external commands.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"This is the opening fence for a Markdown report excerpt. The fenced content is example output, not executable shell or Ruby code.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL is homepage metadata pointing to the source repository. I found no code that makes network requests or transmits data to it.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URL appears inside metadata as a project homepage. It is not used as an endpoint for fetching, posting, or exfiltrating data.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","reason":"The parent-directory sequence is in a Markdown link to a related skill. The documented save path remains under memory and does not traverse arbitrary parent paths.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:45:path-traversal-sequence","reason":"The ../../../ sequence is a Markdown reference to a neighboring skill document. It is not an instruction to read or write arbitrary host files.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","reason":"The ../../../ sequence is a Markdown link to a shared contract reference. It is documentation navigation, not runtime path traversal.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:62:path-traversal-sequence","reason":"The ../../../ sequence is a Markdown link to CONNECTORS.md. It does not direct the agent to access user-controlled paths.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:105:path-traversal-sequence","reason":"This is a reference-material Markdown link to a shared contract file. It is not used for dynamic filesystem access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:106:path-traversal-sequence","reason":"This is a reference-material Markdown link to a shared state-model file. It is not an arbitrary file access instruction.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:107:path-traversal-sequence","reason":"This is a reference-material Markdown link to CONNECTORS.md. It does not read secrets or traverse user-supplied paths.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:108:path-traversal-sequence","reason":"This is a relative Markdown link to a companion skill. It is documentation, not a filesystem traversal operation.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:109:path-traversal-sequence","reason":"This is a relative Markdown link to the ROI calculator skill. It is not dynamic path construction or host file access.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:110:path-traversal-sequence","reason":"This is a relative Markdown link to the campaign planner skill. It does not instruct arbitrary parent-directory reads.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:111:path-traversal-sequence","reason":"This is a relative Markdown link to the content amplifier skill. It is documentation navigation, not path traversal.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:112:path-traversal-sequence","reason":"This is a relative Markdown link to the content quality auditor skill. There is no user-controlled path or sensitive file target.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:116:path-traversal-sequence","reason":"This is a next-skill Markdown link using a relative path. It does not create a traversal vulnerability by itself.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:120:path-traversal-sequence","reason":"This is a relative Markdown link to another marketing skill. It is not a read or write operation against arbitrary filesystem locations.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:SKILL.md:121:path-traversal-sequence","reason":"This is a relative Markdown link to the ROI calculator skill. It does not expose sensitive files or allow attacker-controlled traversal.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:20:system-reconnaissance","reason":"The line describes paid-ads reporting inputs and memory paths for generated reports. It does not ask the agent to discover system information.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:76:system-reconnaissance","reason":"The line tells the skill to save and promote report outputs under fixed memory paths. It is expected workflow state handling, not system reconnaissance.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:123:system-reconnaissance","reason":"The visited-set note prevents repeated skill chaining loops. It is control guidance, not host or network reconnaissance.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}