{"data":{"skill":{"slug":"addyosmani-api-and-interface-design","name":"api-and-interface-design","icon":"📦","repo":"https://github.com/addyosmani/agent-skills/tree/c004a74784a08295d52749b04cda634125b9a581/skills/api-and-interface-design","status":"approved","author":"addyosmani","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"62c53bfc-4dbd-44e3-9d16-d2b8f162987b","skill_id":"f73d21d1-6738-4b80-a4ab-1da932d99b74","version":2,"content_hash":"v3:5d5054f8a23586f9b500fece1cb613a9dffc787b:5dafd0c44a3aabf11cae5bcb34f6fcc24dfa5c01ba6e0d3176bce997f4d68bc8:6c3adc6f27f84eeb9c05c3b73ded9a0c6737a17a1da4a4d642dabdfc62e93420:736b696c6c732f616464796f736d616e692f6170692d616e642d696e746572666163652d64657369676e:0f11fd8a0f1fe434ee86434ec04cd054","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 52 static findings are false positives from Markdown backticks, TypeScript template literals, REST examples, and ordinary API terminology. The skill is documentation-only and contains no shell execution, system reconnaissance, prompt injection, or malicious intent.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":59,"line_start":41},{"file":"SKILL.md","line_end":65,"line_start":59},{"file":"SKILL.md","line_end":84,"line_start":65},{"file":"SKILL.md","line_end":86,"line_start":84},{"file":"SKILL.md","line_end":92,"line_start":86},{"file":"SKILL.md","line_end":110,"line_start":92},{"file":"SKILL.md","line_end":129,"line_start":110},{"file":"SKILL.md","line_end":144,"line_start":129},{"file":"SKILL.md","line_end":150,"line_start":144},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":152,"line_start":151},{"file":"SKILL.md","line_end":153,"line_start":152},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":154,"line_start":154},{"file":"SKILL.md","line_end":162,"line_start":158},{"file":"SKILL.md","line_end":164,"line_start":162},{"file":"SKILL.md","line_end":165,"line_start":164},{"file":"SKILL.md","line_end":168,"line_start":165},{"file":"SKILL.md","line_end":169,"line_start":168},{"file":"SKILL.md","line_end":175,"line_start":169},{"file":"SKILL.md","line_end":191,"line_start":175},{"file":"SKILL.md","line_end":197,"line_start":191},{"file":"SKILL.md","line_end":201,"line_start":197},{"file":"SKILL.md","line_end":207,"line_start":201},{"file":"SKILL.md","line_end":209,"line_start":207},{"file":"SKILL.md","line_end":221,"line_start":209},{"file":"SKILL.md","line_end":230,"line_start":221},{"file":"SKILL.md","line_end":236,"line_start":230},{"file":"SKILL.md","line_end":250,"line_start":236},{"file":"SKILL.md","line_end":256,"line_start":250},{"file":"SKILL.md","line_end":258,"line_start":256},{"file":"SKILL.md","line_end":264,"line_start":258},{"file":"SKILL.md","line_end":268,"line_start":264},{"file":"SKILL.md","line_end":274,"line_start":268},{"file":"SKILL.md","line_end":286,"line_start":274},{"file":"SKILL.md","line_end":287,"line_start":286},{"file":"SKILL.md","line_end":288,"line_start":287},{"file":"SKILL.md","line_end":291,"line_start":288},{"file":"SKILL.md","line_end":295,"line_start":291},{"file":"SKILL.md","line_end":311,"line_start":295},{"file":"SKILL.md","line_end":315,"line_start":311},{"file":"SKILL.md","line_end":321,"line_start":315},{"file":"SKILL.md","line_end":345,"line_start":321},{"file":"SKILL.md","line_end":345,"line_start":345},{"file":"SKILL.md","line_end":347,"line_start":347}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":368,"audit_model":"codex","audited_at":"2026-09-19T11:18:54.459+00:00","created_at":"2026-09-19T13:23:07.680751+00:00","static_findings":[{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Plan for deprecation at design time.** See `deprecation-and-migration` for how to safely remove ","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":59,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":84,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":86,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Don't mix patterns.** If some endpoints throw, others return null, and others return `{ error }` —","category":"external_commands","line_end":92,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":110,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":129,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":144,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":150,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| REST endpoints | Plural nouns, no verbs | `GET /api/tasks`, `POST /api/tasks` |","category":"external_commands","line_end":150,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Query params | camelCase | `?sortBy=createdAt&pageSize=20` |","category":"external_commands","line_end":152,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Response fields | camelCase | `{ createdAt, updatedAt, taskId }` |","category":"external_commands","line_end":153,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Boolean fields | is/has/can prefix | `isComplete`, `hasAttachments` |","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Enum values | UPPER_SNAKE | `\"IN_PROGRESS\"`, `\"COMPLETED\"` |","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Accepting an `Idempotency-Key` is the contract. Honouring it is the implementation, and it is where ","category":"external_commands","line_end":162,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":164,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`${userId}:${amount}`                  // ✗ two legitimate $50 charges collapse into one","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`${orderId}:${Date.now()}`             // ✗ a timestamp is randomUUID() wearing a hat","category":"external_commands","line_end":168,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`charge:v1:${orderId}`                 // ✓ derived from an immutable identifier","category":"external_commands","line_end":169,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":175,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":191,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":197,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":201,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":207,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Reject | `409 Conflict` | Client can retry later; simplest and safest |","category":"external_commands","line_end":209,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Return pending | `202` + status URL | Long-running effects |","category":"external_commands","line_end":221,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":230,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":236,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":250,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":256,"severity":"medium","line_start":250},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":258,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":264,"severity":"medium","line_start":258},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":268,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":274,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":286,"severity":"medium","line_start":274},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"case 'in_progress': return `In progress (${status.assignee})`;","category":"external_commands","line_end":287,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"case 'completed': return `Done on ${status.completedAt}`;","category":"external_commands","line_end":288,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"case 'cancelled': return `Cancelled: ${status.reason}`;","category":"external_commands","line_end":291,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":295,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":311,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":315,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":321,"severity":"medium","line_start":315},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":345,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Verbs in REST URLs (`/api/createTask`, `/api/getUsers`)","category":"external_commands","line_end":345,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- A `SELECT` for an idempotency key followed by an `INSERT` — that's a race, not a guard","category":"external_commands","line_end":347,"severity":"medium","line_start":347},{"id":"blocker:SKILL.md:35:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Avoid forcing consumers to choose between multiple versions of the same dependency or API. Diamond d","category":"blocker","line_end":35,"severity":"low","line_start":35},{"id":"blocker:SKILL.md:77:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"// 400 → Client sent invalid data","category":"blocker","line_end":77,"severity":"low","line_start":77},{"id":"blocker:SKILL.md:100:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"message: 'Invalid task data',","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:SKILL.md:224:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"GET    /api/tasks/:id          → Get a single task","category":"blocker","line_end":224,"severity":"low","line_start":224},{"id":"blocker:SKILL.md:225:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"PATCH  /api/tasks/:id          → Update a task (partial)","category":"blocker","line_end":225,"severity":"low","line_start":225},{"id":"blocker:SKILL.md:226:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"DELETE /api/tasks/:id          → Delete a task","category":"blocker","line_end":226,"severity":"low","line_start":226}],"finding_verdicts":[{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The match is an inline Markdown reference to another skill, not executable shell syntax. The surrounding text discusses API deprecation planning.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The finding covers a fenced TypeScript interface example. It defines API methods and contains no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown TypeScript code block. They do not invoke a command or interpreter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The finding is within a fenced TypeScript example about structured errors. No process execution or shell input is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The match closes a Markdown code block containing HTTP error guidance. It is formatting, not external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticks appear in prose and examples describing consistent error patterns. No executable command is supplied.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The match is the opening fence for a TypeScript validation example. The example documents request validation and does not run a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The matched fence closes a TypeScript API handler example. It is Markdown syntax and has no command execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The opening TypeScript fence introduces validation guidance for external inputs. It does not represent Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The closing Markdown fence ends a TypeScript example about additive interface changes. No external command is executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"The match is an inline REST endpoint example in a documentation table. It is a literal API path, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The matched text is a query parameter naming example. It contains no executable syntax or external process invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The backticks quote response field names in documentation. They do not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The match documents boolean field naming conventions. It is an inline code example, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The match documents enum naming conventions with quoted values. No command or interpreter is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The backticks quote an HTTP header name in prose about idempotency. This is documentation, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The opening fence starts a TypeScript idempotency example. The code discusses key derivation and does not invoke an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"This is a TypeScript template literal used as an illustrative idempotency key. It is not a Ruby backtick expression or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"This is a TypeScript template literal shown as a poor key design. It performs string interpolation only and does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"This TypeScript template literal illustrates a stable key format. It produces a string and has no process execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The matched fence closes a TypeScript code example about idempotency keys. Markdown formatting is not an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The opening TypeScript fence introduces an atomic idempotency example. No shell, Ruby, or process execution appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The closing fence ends a TypeScript database coordination example. It is documentation syntax with no executable shell behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"The opening fence starts a TypeScript payload-checking example. The example validates request data and does not execute external commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"The closing Markdown fence ends the TypeScript payload-checking example. It is not an execution primitive.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"The backticks quote an HTTP status and response strategy in a table. This is API documentation, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The matched text describes a 202 response strategy for duplicate requests. It contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"The closing fence ends an API request-response example. The Markdown fence cannot execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"The matched fence closes a pagination example. It is a documentation delimiter, not external command syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The opening TypeScript fence introduces a filtering example. The content describes API query parameters and has no process execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","reason":"The closing fence ends a TypeScript partial-update example. It is Markdown formatting with no shell behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"The matched fence closes an API request example. It does not invoke a command or interpret user input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","reason":"The opening fence starts a TypeScript discriminated-union example. It is explanatory code, not external process execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The matched fence closes a TypeScript union example. No shell command, Ruby expression, or dynamic execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The closing fence ends a TypeScript status-label example. Markdown delimiters do not execute the template literals.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","reason":"The opening TypeScript fence introduces input and output interface examples. It contains no external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"This TypeScript template literal formats a status label. It performs string interpolation and cannot execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"This TypeScript template literal formats a completion date for an example label. It is not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"This TypeScript template literal formats a cancellation reason. It only creates a string in an illustrative function.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The closing fence ends a TypeScript status-label example. It is Markdown syntax and does not run an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The opening TypeScript fence introduces branded type guidance. It is an explanatory code block with no process execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The closing fence ends a TypeScript interface example. It is documentation formatting, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","reason":"The opening fence starts a TypeScript input-output separation example. No external command or dynamic evaluator is used.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"The closing fence ends the TypeScript input-output example. The matched backticks only delimit Markdown code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"The backticks quote REST URL anti-patterns in a red-flags list. They are literal documentation examples, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","reason":"The backticks quote a database race anti-pattern in documentation. No command execution is described or performed.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:35:system-reconnaissance","reason":"The line discusses dependency and API versioning under the One-Version Rule. It is design guidance, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:77:system-reconnaissance","reason":"The line documents an HTTP 400 status mapping in an API error example. It does not inspect or enumerate a host system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:100:system-reconnaissance","reason":"The line is a sample validation error message for an API request. It contains no reconnaissance instruction or system query.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:224:system-reconnaissance","reason":"The line documents a GET endpoint for retrieving a task. It is an API design example, not host or environment discovery.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:225:system-reconnaissance","reason":"The line documents a PATCH endpoint for partial updates. It does not perform system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:226:system-reconnaissance","reason":"The line documents a DELETE endpoint for a task resource. It is a REST example and contains no host inspection behavior.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"5d5054f8a23586f9b500fece1cb613a9dffc787b","subject_content_hash":"5dafd0c44a3aabf11cae5bcb34f6fcc24dfa5c01ba6e0d3176bce997f4d68bc8","subject_tree_hash":"6c3adc6f27f84eeb9c05c3b73ded9a0c6737a17a1da4a4d642dabdfc62e93420","subject_plugin_path":"skills/addyosmani/api-and-interface-design","audit_payload_hash":"0f11fd8a0f1fe434ee86434ec04cd054","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"5d5054f8a23586f9b500fece1cb613a9dffc787b","contentHash":"5dafd0c44a3aabf11cae5bcb34f6fcc24dfa5c01ba6e0d3176bce997f4d68bc8","treeHash":"6c3adc6f27f84eeb9c05c3b73ded9a0c6737a17a1da4a4d642dabdfc62e93420","pluginPath":"skills/addyosmani/api-and-interface-design","auditPayloadHash":"0f11fd8a0f1fe434ee86434ec04cd054"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/addyosmani-api-and-interface-design/audits/2/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}