{"data":{"skill":{"slug":"addyosmani-spec-driven-development","name":"spec-driven-development","icon":"📦","repo":"https://github.com/addyosmani/agent-skills/tree/be4e44a9fbc5e8df0beaefadbb28bd22ee61cc39/skills/spec-driven-development","status":"approved","author":"addyosmani","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"5417de57-aa15-464e-8b2e-89603b53620d","skill_id":"7c66ac1c-2197-4e74-809d-ed86fb097066","version":1,"content_hash":"v3:5526951beaeca22519572a471618555839b53b05:f7129bca8742bad73f60209bd237e8b10dab6f1fae8576dc552fb1923bc1e721:84f95a1faf9434c257eb01f0aab2a7942103c6f633ddd332cebc881dfc47cdb1:736b696c6c732f616464796f736d616e692f737065632d64726976656e2d646576656c6f706d656e74:716dc784679966c701307f63f347dc65","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 26 static findings are false positives caused by Markdown fences, inline code formatting, tables, and workflow prose. No executable shell or Ruby code, prompt injection, or malicious semantic behavior was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":32,"line_start":26},{"file":"SKILL.md","line_end":46,"line_start":32},{"file":"SKILL.md","line_end":57,"line_start":46},{"file":"SKILL.md","line_end":61,"line_start":57},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":80,"line_start":73},{"file":"SKILL.md","line_end":89,"line_start":80},{"file":"SKILL.md","line_end":94,"line_start":89},{"file":"SKILL.md","line_end":97,"line_start":94},{"file":"SKILL.md","line_end":104,"line_start":97},{"file":"SKILL.md","line_end":117,"line_start":104},{"file":"SKILL.md","line_end":148,"line_start":117},{"file":"SKILL.md","line_end":153,"line_start":148},{"file":"SKILL.md","line_end":158,"line_start":153},{"file":"SKILL.md","line_end":166,"line_start":158},{"file":"SKILL.md","line_end":180,"line_start":166},{"file":"SKILL.md","line_end":180,"line_start":180},{"file":"SKILL.md","line_end":182,"line_start":182},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":204,"line_start":199},{"file":"SKILL.md","line_end":208,"line_start":204},{"file":"SKILL.md","line_end":208,"line_start":208}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":252,"audit_model":"codex","audited_at":"2026-09-12T11:54:30.775+00:00","created_at":"2026-09-14T00:39:52.655133+00:00","static_findings":[{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":46,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":57,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":61,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Interfaces live at the boundary.** The map records that `billing` depends on `identity`; the con","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Then recurse per module.** Run Specify → Plan → Tasks → Implement for each module in dependency or","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":89,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":94,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":97,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":104,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":117,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":148,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":153,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`SPEC.md`. This skill owns the clarification, content, and approval gates; the","category":"external_commands","line_end":158,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":166,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":180,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Follow `planning-and-task-breakdown` for the dependency-graph mapping and vertical-slicing mechani","category":"external_commands","line_end":180,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **Output convention:** Save the plan to `tasks/plan.md` and record the task list in the task list ","category":"external_commands","line_end":182,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Follow `planning-and-task-breakdown` for the full task-sizing and dependency-ordering mechanics; i","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":204,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":208,"severity":"medium","line_start":204},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Execute tasks one at a time following `skills/incremental-implementation/SKILL.md` (`incremental-imp","category":"external_commands","line_end":208,"severity":"medium","line_start":208},{"id":"blocker:SKILL.md:49:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Module id | Responsibility | Depends on |","category":"blocker","line_end":49,"severity":"low","line_start":49},{"id":"blocker:SKILL.md:65:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"**Then recurse per module.** Run Specify → Plan → Tasks → Implement for each module in dependency or","category":"blocker","line_end":65,"severity":"low","line_start":65},{"id":"blocker:SKILL.md:251:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- [ ] Every module spec traces to a module id in the approved map","category":"blocker","line_end":251,"severity":"low","line_start":251}],"finding_verdicts":[{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Lines 26-32 are a fenced text diagram of workflow phases. The backticks delimit Markdown and do not execute Ruby or shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"Line 32 closes a Markdown fence around a text diagram. No executable interpreter context or command invocation exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Lines 46-57 are a fenced Markdown capability-map example. The backticks are documentation syntax, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Line 57 closes the capability-map Markdown example. It contains no Ruby expression or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"Line 61 uses inline backticks for module names and a related skill name. These are literal documentation labels.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"Line 65 uses inline backticks for example specification filenames. It describes file naming and does not invoke a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"Lines 73-80 are a fenced assumptions example. The fence presents text and has no executable language context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"Line 80 closes a fenced prose example. It cannot trigger shell or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"Lines 89-94 show build, test, lint, and development commands as specification content. They are documentation examples, not instructions to execute hidden commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"Line 94 closes the documented command example. The Markdown fence itself is not an execution mechanism.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"Lines 97-104 are a fenced directory-layout example. No command, interpreter, or user-controlled execution path is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"Line 104 closes the project-structure example. This is Markdown formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"Lines 117-148 are a fenced Markdown specification template. The content is a document outline and has no executable behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"Line 148 closes the specification template fence. It does not call Ruby, a shell, or any external process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"Line 153 formats the filename SPEC.md with inline backticks. It is a literal artifact name, not executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"Lines 158-166 are a fenced example that converts a vague requirement into measurable criteria. The fence contains plain text only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"Line 166 closes a prose example. There is no dynamic evaluation or command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"Line 180 uses inline backticks to reference another skill by name. This is a documentation link convention, not external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"Line 182 uses inline backticks for output paths and a downstream command name. It describes expected artifacts without embedding executable shell syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"Line 196 formats a related skill name with inline backticks. The text delegates planning guidance and does not launch a process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"Lines 199-204 are a fenced Markdown task template. The checklist fields are documentation placeholders, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","reason":"Line 204 closes the task-template fence. Markdown delimiters do not invoke an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"Line 208 uses inline backticks for local skill paths and names. It references development workflows but contains no shell or Ruby execution construct.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:49:system-reconnaissance","reason":"Line 49 is a table header for a proposed capability map. It requests no system information and performs no reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:65:system-reconnaissance","reason":"Line 65 explains how to process approved modules in dependency order. It neither probes the host system nor collects sensitive environment data.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:251:system-reconnaissance","reason":"Line 251 is a verification checkbox linking module specifications to approved module identifiers. It is project-document validation, not system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"5526951beaeca22519572a471618555839b53b05","subject_content_hash":"f7129bca8742bad73f60209bd237e8b10dab6f1fae8576dc552fb1923bc1e721","subject_tree_hash":"84f95a1faf9434c257eb01f0aab2a7942103c6f633ddd332cebc881dfc47cdb1","subject_plugin_path":"skills/addyosmani/spec-driven-development","audit_payload_hash":"716dc784679966c701307f63f347dc65","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"5526951beaeca22519572a471618555839b53b05","contentHash":"f7129bca8742bad73f60209bd237e8b10dab6f1fae8576dc552fb1923bc1e721","treeHash":"84f95a1faf9434c257eb01f0aab2a7942103c6f633ddd332cebc881dfc47cdb1","pluginPath":"skills/addyosmani/spec-driven-development","auditPayloadHash":"716dc784679966c701307f63f347dc65"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/addyosmani-spec-driven-development/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}