{"data":{"skill":{"slug":"aaron-he-zhu-roi-calculator","name":"roi-calculator","icon":"📦","repo":"https://github.com/aaron-he-zhu/aaron-marketing-skills/tree/main/influencer/measure/roi-calculator","status":"approved","author":"aaron-he-zhu","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"422e6b11-4378-4ad0-a4a3-15db2a1c6ad5","skill_id":"f58a055e-3f7e-42f0-8fdc-e6863c282762","version":3,"content_hash":"v2:7ed2830f0283f3a8900137d8dc893e54072206f3:3e174b30e0be4a6a06e4324ecac572ed816489c2009b97389d0edcc696555287:3f646a6590d2e4f8578fa164fb7ce588556b3c4a7f6b2ef1e0c16c62f822ebbf:6f3d922a43a40ce0d897408c8cc18956","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Reviewed 42 static findings across SKILL.md and references/roi-templates.md. The detections are false positives from markdown links, examples, inline labels, placeholders, and homepage metadata; no command execution, network call, prompt injection, or malicious file access intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/roi-templates.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":136,"line_start":136},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":138,"line_start":138},{"file":"SKILL.md","line_end":139,"line_start":139},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":141,"line_start":141},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":143,"line_start":143},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":148,"line_start":148},{"file":"SKILL.md","line_end":152,"line_start":152},{"file":"SKILL.md","line_end":153,"line_start":153}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":28,"line_start":26},{"file":"SKILL.md","line_end":32,"line_start":28},{"file":"SKILL.md","line_end":34,"line_start":32},{"file":"SKILL.md","line_end":38,"line_start":34},{"file":"SKILL.md","line_end":39,"line_start":38},{"file":"SKILL.md","line_end":40,"line_start":39},{"file":"SKILL.md","line_end":55,"line_start":40},{"file":"SKILL.md","line_end":56,"line_start":55},{"file":"SKILL.md","line_end":57,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":57},{"file":"SKILL.md","line_end":86,"line_start":58},{"file":"SKILL.md","line_end":88,"line_start":86},{"file":"SKILL.md","line_end":90,"line_start":88},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":129,"line_start":98}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":13,"line_start":13}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":584,"audit_model":"codex","audited_at":"2026-07-07T06:41:29.155+00:00","created_at":"2026-07-07T08:33:08.630247+00:00","static_findings":[{"id":"filesystem:references/roi-templates.md:3:path-traversal-sequence","file":"references/roi-templates.md","pattern":"Path traversal sequence","snippet":"Fill-in templates for each methodology in [../SKILL.md](../SKILL.md) Instructions, plus the worked e","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"blocker:references/roi-templates.md:21:system-reconnaissance","file":"references/roi-templates.md","pattern":"System reconnaissance","snippet":"| Paid amplification | $[X] |","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"blocker:references/roi-templates.md:85:system-reconnaissance","file":"references/roi-templates.md","pattern":"System reconnaissance","snippet":"EMV estimates the equivalent paid media cost to achieve the same results.","category":"blocker","line_end":85,"severity":"low","line_start":85},{"id":"blocker:references/roi-templates.md:168:system-reconnaissance","file":"references/roi-templates.md","pattern":"System reconnaissance","snippet":"| Paid Social | $[X] | [+/-X%] |","category":"blocker","line_end":168,"severity":"low","line_start":168},{"id":"blocker:references/roi-templates.md:169:system-reconnaissance","file":"references/roi-templates.md","pattern":"System reconnaissance","snippet":"| Paid Search | $[X] | [+/-X%] |","category":"blocker","line_end":169,"severity":"low","line_start":169},{"id":"blocker:references/roi-templates.md:261:system-reconnaissance","file":"references/roi-templates.md","pattern":"System reconnaissance","snippet":"| Indicator | Influencer-Acquired | Organic | Paid Ads |","category":"blocker","line_end":261,"severity":"low","line_start":261},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **Cross-discipline (paid ads):** this is the shared **return-math engine** for paid ads — [paid-me","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":34,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Reads**: campaign spend breakdown, results data (reach, impressions, engagements, clicks, conver","category":"external_commands","line_end":39,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Writes**: ROI calculation file at `memory/influencer/roi-calculator/YYYY-MM-DD-<topic>.md` conta","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Promotes**: durable headline numbers (final ROI %, ROAS, total investment, net profit, recommend","category":"external_commands","line_end":55,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~social platform analytics` — reach, impressions, engagements, video views per platform for EMV ","category":"external_commands","line_end":56,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~ecommerce / analytics` — revenue, conversions, link clicks, and AOV for direct ROI and attribut","category":"external_commands","line_end":57,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~CRM` — new-customer counts, repeat-purchase rate, and lifetime value for LTV-based ROI.","category":"external_commands","line_end":58,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `~~influencer database` — per-influencer fees and tier data for by-influencer ROI.","category":"external_commands","line_end":86,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":88,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":90,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`ACE_avg` is the **budget-weighted** mean of the campaign's creator ACE scores; `ART_avg` is the sim","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":129,"severity":"medium","line_start":98},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"homepage: \"https://github.com/aaron-he-zhu/aaron-marketing-skills\"","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"author\": \"aaron-he-zhu\", \"version\": \"16.0.1\", \"discipline\": \"influencer\", \"phase\": \"meas","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> **Cross-discipline (paid ads):** this is the shared **return-math engine** for paid ads — [paid-me","category":"filesystem","line_end":20,"severity":"high","line_start":20},{"id":"filesystem:SKILL.md:45:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- **Primary next skill**: [report-generator](../report-generator/SKILL.md)","category":"filesystem","line_end":45,"severity":"high","line_start":45},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> Emit the standard shape from [skill-contract.md §Handoff Summary Format](../../../references/skill","category":"filesystem","line_end":49,"severity":"high","line_start":49},{"id":"filesystem:SKILL.md:60:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"With zero integrations, supply the investment and results tables by hand and the skill still produce","category":"filesystem","line_end":60,"severity":"high","line_start":60},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"This skill emits the **ROI** scope score of [C3](../../../references/c3-benchmark.md) and the **CVI*","category":"filesystem","line_end":84,"severity":"high","line_start":84},{"id":"filesystem:SKILL.md:136:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [measurement-protocol.md](../../../references/measurement-protocol.md) — read ROI/CVI deltas again","category":"filesystem","line_end":136,"severity":"high","line_start":136},{"id":"filesystem:SKILL.md:137:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [skill-contract.md](../../../references/skill-contract.md) — shared contract and Handoff Summary f","category":"filesystem","line_end":137,"severity":"high","line_start":137},{"id":"filesystem:SKILL.md:138:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [state-model.md](../../../references/state-model.md) — memory tiers and save-path conventions.","category":"filesystem","line_end":138,"severity":"high","line_start":138},{"id":"filesystem:SKILL.md:139:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [CONNECTORS.md](../../../CONNECTORS.md) — free/keyless data recipe per connector category.","category":"filesystem","line_end":139,"severity":"high","line_start":139},{"id":"filesystem:SKILL.md:140:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- C3 scoring: [c3-benchmark.md](../../../references/c3-benchmark.md) (CVI rollup formula) and [c3/ro","category":"filesystem","line_end":140,"severity":"high","line_start":140},{"id":"filesystem:SKILL.md:141:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [performance-analyzer](../performance-analyzer/SKILL.md) — supplies the results data this skill co","category":"filesystem","line_end":141,"severity":"high","line_start":141},{"id":"filesystem:SKILL.md:142:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [report-generator](../report-generator/SKILL.md) — wraps these numbers into a full report.","category":"filesystem","line_end":142,"severity":"high","line_start":142},{"id":"filesystem:SKILL.md:143:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [budget-optimizer](../../plan/budget-optimizer/SKILL.md) — uses ROI output to reallocate spend.","category":"filesystem","line_end":143,"severity":"high","line_start":143},{"id":"filesystem:SKILL.md:144:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [campaign-planner](../../plan/campaign-planner/SKILL.md) — sets the ROI targets these results are ","category":"filesystem","line_end":144,"severity":"high","line_start":144},{"id":"filesystem:SKILL.md:148:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"**Primary**: [report-generator](../report-generator/SKILL.md) — turn the ROI numbers into a stakehol","category":"filesystem","line_end":148,"severity":"high","line_start":148},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [performance-analyzer](../performance-analyzer/SKILL.md) — go back for deeper performance breakdow","category":"filesystem","line_end":152,"severity":"high","line_start":152},{"id":"filesystem:SKILL.md:153:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- [budget-optimizer](../../plan/budget-optimizer/SKILL.md) — feed by-influencer and by-tier ROI into","category":"filesystem","line_end":153,"severity":"high","line_start":153},{"id":"blocker:SKILL.md:20:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"> **Cross-discipline (paid ads):** this is the shared **return-math engine** for paid ads — [paid-me","category":"blocker","line_end":20,"severity":"low","line_start":20}],"finding_verdicts":[{"id":"filesystem:references/roi-templates.md:3:path-traversal-sequence","reason":"Line 3 is a markdown link from the templates file back to SKILL.md. It is documentation navigation, not user-controlled filesystem access.","verdict":"false_positive","confidence":0.94},{"id":"blocker:references/roi-templates.md:21:system-reconnaissance","reason":"Line 21 is a placeholder row for paid amplification spend in an ROI input table. It does not request host, network, or system reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/roi-templates.md:85:system-reconnaissance","reason":"Line 85 explains earned media value as a marketing metric. It does not instruct the agent to inspect system state.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/roi-templates.md:168:system-reconnaissance","reason":"Line 168 is a paid social comparison row in a campaign benchmark table. The word paid is marketing context, not reconnaissance behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/roi-templates.md:169:system-reconnaissance","reason":"Line 169 is a paid search comparison row in a campaign benchmark table. It does not request system discovery or sensitive data collection.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/roi-templates.md:261:system-reconnaissance","reason":"Line 261 compares customer quality across organic and paid ads channels. This is marketing analysis terminology, not system reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"Line 20 uses markdown links and inline code for a memory path. It contains no Ruby backtick execution or shell command.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Lines 26-28 are a fenced markdown example showing a natural-language user prompt. The backticks delimit documentation, not executable code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"Line 28 closes a markdown fence around a user prompt example. It does not execute a command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"Lines 32-34 are a fenced markdown example with a question about ROI methods. The backticks are formatting only.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"Line 34 closes a markdown fence around a non-executable ROI question. No shell or interpreter is invoked.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"Line 38 describes business inputs and references performance-analyzer as an inline code label. It does not contain command execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"Line 39 names a markdown output path under memory/influencer/roi-calculator. It is a bounded report destination, not shell execution.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"Line 40 names memory/hot-cache.md as a place for durable headline metrics. The inline code marks a file path, not a command.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Line 55 uses inline code to label a social platform analytics connector category. It does not run a shell command.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"Line 56 uses inline code to label an ecommerce or analytics connector category. It contains no executable command.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Line 57 uses inline code for a CRM connector label. It is documentation text, not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Line 58 uses inline code for an influencer database connector label. It does not instruct command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"Lines 86-88 fence a CVI formula in markdown. The backticks are display formatting, not executable syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"Line 88 closes the markdown fence for the CVI formula. No command interpreter is involved.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"Line 90 uses inline code for metric names such as ACE_avg and ART_avg. These are calculation labels, not commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"Lines 98-129 are a fenced markdown sample output. The fence is documentation formatting and contains no executable instructions.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:10:hardcoded-url","reason":"Line 10 stores a GitHub homepage URL in frontmatter metadata. It does not make a network request or send data externally.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:13:hardcoded-url","reason":"Line 13 repeats the GitHub homepage URL inside metadata. It is descriptive package metadata, not active network behavior.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:20:path-traversal-sequence","reason":"Line 20 links to neighboring paid ads skills and names a memory path. The relative links are documentation references, not dynamic path traversal.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:SKILL.md:45:path-traversal-sequence","reason":"Line 45 links to a sibling report-generator skill as the next workflow step. It does not read arbitrary user-controlled paths.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:49:path-traversal-sequence","reason":"Line 49 points to a shared skill-contract reference document. This is static documentation navigation, not unsafe filesystem access.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:60:path-traversal-sequence","reason":"Line 60 links to CONNECTORS.md for data-source guidance. The path is a fixed documentation link, not a traversal primitive.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:84:path-traversal-sequence","reason":"Line 84 links to shared benchmark files and related skills for CVI scoring. These are fixed markdown references, not user-supplied paths.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:SKILL.md:136:path-traversal-sequence","reason":"Line 136 references measurement-protocol.md in the repository documentation. It is not a runtime file-access instruction against arbitrary paths.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:137:path-traversal-sequence","reason":"Line 137 references skill-contract.md as shared documentation. The traversal sequence appears only in a static markdown link.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:138:path-traversal-sequence","reason":"Line 138 references state-model.md for memory conventions. It is a fixed documentation link, not an unsafe path operation.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:139:path-traversal-sequence","reason":"Line 139 references CONNECTORS.md for connector guidance. The link is static documentation and contains no user input.","verdict":"false_positive","confidence":0.91},{"id":"filesystem:SKILL.md:140:path-traversal-sequence","reason":"Line 140 references shared C3 benchmark documents. These are fixed repository documentation links, not arbitrary filesystem traversal.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:SKILL.md:141:path-traversal-sequence","reason":"Line 141 links to a sibling performance-analyzer skill. It is a static workflow reference and does not access user-controlled paths.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:142:path-traversal-sequence","reason":"Line 142 links to a sibling report-generator skill. The relative path is documentation navigation, not path traversal abuse.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:143:path-traversal-sequence","reason":"Line 143 links to a sibling budget-optimizer skill. It is a fixed markdown reference and contains no unsafe file operation.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:144:path-traversal-sequence","reason":"Line 144 links to a sibling campaign-planner skill. It is a static reference to related workflow guidance.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:148:path-traversal-sequence","reason":"Line 148 repeats the report-generator sibling skill link as the primary next skill. This is workflow documentation, not filesystem traversal.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:152:path-traversal-sequence","reason":"Line 152 links to performance-analyzer as an alternate next skill. The fixed markdown link is not an arbitrary path read.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:153:path-traversal-sequence","reason":"Line 153 links to budget-optimizer as an alternate next skill. It is static documentation, not traversal-based file access.","verdict":"false_positive","confidence":0.93},{"id":"blocker:SKILL.md:20:system-reconnaissance","reason":"Line 20 uses paid ads as marketing context for ROI math. It does not ask the agent to inventory the system or collect host information.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}