{"data":{"skill":{"slug":"addyosmani-debugging-and-error-recovery","name":"debugging-and-error-recovery","icon":"📦","repo":"https://github.com/addyosmani/agent-skills/tree/be4e44a9fbc5e8df0beaefadbb28bd22ee61cc39/skills/debugging-and-error-recovery","status":"approved","author":"addyosmani","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"a9935df8-b742-4045-8107-4ecfe79030b6","skill_id":"b2b1779e-a369-4e2d-bfd2-5d44bdc005a7","version":1,"content_hash":"v3:5526951beaeca22519572a471618555839b53b05:21f3960f5d7ae2cc95c40896545004dbbcbbd752ea65fc2d53962554d4174220:9bf24bcc8006552dd96983e91fa008eb4d375463887554f13d4cad12ad125769:736b696c6c732f616464796f736d616e692f646562756767696e672d616e642d6572726f722d7265636f76657279:e6a07aed7465c2fe2596b2fea4393348","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 32 static findings are false positives because they identify Markdown fences, example commands, a configuration lookup, or ordinary troubleshooting text rather than executable malware. No prompt injection, data-exfiltration intent, or malicious behavior was found in SKILL.md.","remediation":[{"issue":"Shell commands appear in troubleshooting examples and may be copied without reviewing their scope.","severity":"low","suggestion":"Keep commands narrowly scoped and require user confirmation before running commands that change files, history, dependencies, or environments."},{"issue":"The configuration example reads an environment variable and logs a missing key.","severity":"low","suggestion":"Keep environment values out of logs and document that diagnostic output must exclude secrets."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":32,"line_start":25},{"file":"SKILL.md","line_end":44,"line_start":32},{"file":"SKILL.md","line_end":51,"line_start":44},{"file":"SKILL.md","line_end":55,"line_start":51},{"file":"SKILL.md","line_end":73,"line_start":55},{"file":"SKILL.md","line_end":76,"line_start":73},{"file":"SKILL.md","line_end":85,"line_start":76},{"file":"SKILL.md","line_end":91,"line_start":85},{"file":"SKILL.md","line_end":99,"line_start":91},{"file":"SKILL.md","line_end":102,"line_start":99},{"file":"SKILL.md","line_end":109,"line_start":102},{"file":"SKILL.md","line_end":125,"line_start":109},{"file":"SKILL.md","line_end":134,"line_start":125},{"file":"SKILL.md","line_end":142,"line_start":134},{"file":"SKILL.md","line_end":150,"line_start":142},{"file":"SKILL.md","line_end":158,"line_start":150},{"file":"SKILL.md","line_end":170,"line_start":158},{"file":"SKILL.md","line_end":176,"line_start":170},{"file":"SKILL.md","line_end":186,"line_start":176},{"file":"SKILL.md","line_end":190,"line_start":186},{"file":"SKILL.md","line_end":197,"line_start":190},{"file":"SKILL.md","line_end":201,"line_start":197},{"file":"SKILL.md","line_end":212,"line_start":201},{"file":"SKILL.md","line_end":218,"line_start":212},{"file":"SKILL.md","line_end":223,"line_start":218},{"file":"SKILL.md","line_end":241,"line_start":223}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":221,"line_start":221},{"file":"SKILL.md","line_end":221,"line_start":221}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":301,"audit_model":"codex","audited_at":"2026-09-12T11:54:29.831+00:00","created_at":"2026-09-14T00:39:05.837969+00:00","static_findings":[{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":44,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":51,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":55,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":73,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":76,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":85,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":91,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":99,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":102,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":109,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":125,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":134,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":142,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":150,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":158,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":170,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":176,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":186,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":190,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":197,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":201,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":212,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":218,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":223,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"console.warn(`Missing config: ${key}, using default`);","category":"external_commands","line_end":241,"severity":"medium","line_start":223},{"id":"env_access:SKILL.md:221:environment-variable-access-bracket-notation","file":"SKILL.md","pattern":"Environment variable access (bracket notation)","snippet":"const value = process.env[key];","category":"env_access","line_end":221,"severity":"low","line_start":221},{"id":"env_access:SKILL.md:221:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"const value = process.env[key];","category":"env_access","line_end":221,"severity":"low","line_start":221},{"id":"sensitive:SKILL.md:221:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"const value = process.env[key];","category":"sensitive","line_end":221,"severity":"high","line_start":221},{"id":"blocker:SKILL.md:178:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"├── Did you change code the test covers?","category":"blocker","line_end":178,"severity":"low","line_start":178},{"id":"blocker:SKILL.md:182:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"├── Did you change unrelated code?","category":"blocker","line_end":182,"severity":"low","line_start":182},{"id":"blocker:SKILL.md:298:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- [ ] All existing tests pass","category":"blocker","line_end":299,"severity":"low","line_start":298}],"finding_verdicts":[{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Line 25 starts a Markdown code fence for a numbered stop-the-line checklist. It does not execute a shell command or contain Ruby backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The reported range ends a Markdown checklist and begins explanatory prose. The backticks are documentation delimiters, not executable command syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"Lines 44 through 51 contain a fenced troubleshooting decision tree. This is instructional Markdown with no execution context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The reported location closes a Markdown decision-tree example. It does not invoke an external process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Lines 55 through 73 are a fenced list of diagnostic questions and suggestions. The detected backticks are Markdown delimiters.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"Line 73 closes a fenced troubleshooting example. No executable Ruby or shell expression is present at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"Lines 76 through 85 are a fenced Bash example showing test commands for a human to review and run. The skill itself does not execute them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"Line 85 closes a fenced Bash example. This documentation marker is not external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"Lines 91 through 99 contain a fenced layer-localization diagram. The detected backticks delimit documentation only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"Line 99 closes a Markdown diagnostic diagram. It contains no command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"Lines 102 through 109 show a fenced Bash git-bisect example. It is static guidance and has no execution mechanism in the skill.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"Line 109 closes the fenced git-bisect example. The Markdown fence is not a shell execution primitive.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"Lines 125 through 134 are a fenced text comparison of symptom and root-cause fixes. They do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"Line 134 closes a fenced explanatory example. No shell or Ruby execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"Lines 142 through 150 contain a fenced TypeScript regression-test example. The code is illustrative text in SKILL.md, not code run by the skill.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"Line 150 closes the illustrative TypeScript test block. It is a Markdown delimiter, not external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"Lines 158 through 170 are a fenced Bash verification example. The commands are user-facing documentation with no automatic execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"Line 170 closes a fenced verification example. No executable code path exists in this Markdown file.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"Lines 176 through 186 contain a fenced test-failure decision tree. The detected backticks are documentation formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"Line 186 closes a fenced decision tree and does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"Lines 190 through 197 are a fenced build-failure decision tree. This is static instructional content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"Line 197 closes a fenced build-triage example. It contains no execution context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"Lines 201 through 212 contain a fenced runtime-error decision tree. The Markdown example cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"Line 212 closes a fenced runtime-triage example. No external process is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"Lines 218 through 223 are part of a fenced TypeScript configuration example. The source is documentation and has no runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"The template literal on line 223 formats a warning message in an illustrative function. It is not Ruby shell execution and does not invoke a process.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:221:environment-variable-access-bracket-notation","reason":"Line 221 shows a conventional configuration lookup using process.env[key]. It is illustrative code and does not transmit or expose the value.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:221:environment-variable-object","reason":"The environment object is read only to retrieve a named configuration value in a safe-fallback example. No secret disclosure or exfiltration behavior is shown.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:221:environment-file-access","reason":"Line 221 accesses process.env, not an environment file. The example returns a value for local configuration and contains no file read or network transfer.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:178:system-reconnaissance","reason":"Line 178 asks whether changed code is covered by a failing test. This is ordinary debugging triage, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:182:system-reconnaissance","reason":"Line 182 asks whether unrelated code changed during a failure. It is a harmless diagnostic question with no reconnaissance action.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:298:network-reconnaissance","reason":"Line 298 is a checklist item confirming that existing tests pass. It does not inspect or probe a network.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"5526951beaeca22519572a471618555839b53b05","subject_content_hash":"21f3960f5d7ae2cc95c40896545004dbbcbbd752ea65fc2d53962554d4174220","subject_tree_hash":"9bf24bcc8006552dd96983e91fa008eb4d375463887554f13d4cad12ad125769","subject_plugin_path":"skills/addyosmani/debugging-and-error-recovery","audit_payload_hash":"e6a07aed7465c2fe2596b2fea4393348","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"5526951beaeca22519572a471618555839b53b05","contentHash":"21f3960f5d7ae2cc95c40896545004dbbcbbd752ea65fc2d53962554d4174220","treeHash":"9bf24bcc8006552dd96983e91fa008eb4d375463887554f13d4cad12ad125769","pluginPath":"skills/addyosmani/debugging-and-error-recovery","auditPayloadHash":"e6a07aed7465c2fe2596b2fea4393348"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/addyosmani-debugging-and-error-recovery/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}