{"data":{"skill":{"slug":"agentspace-so-happyhorse-1-0","name":"happyhorse-1-0","icon":"📦","repo":"https://github.com/agentspace-so/runcomfy-agent-skills/tree/main/happyhorse-1-0/","status":"approved","author":"agentspace-so","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"290c7423-81e2-4527-805a-c8430332e623","skill_id":"6dc783c3-c1bb-406b-87c3-27e6ed80b487","version":1,"content_hash":"815ec75c9b7823024c7bf1e6147d7d7d","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged 86 potential issues, but evaluation reveals most are false positives. The skill is a legitimate RunComfy CLI wrapper for video generation. Backtick detections are markdown code formatting, not Ruby execution. Network calls go to documented RunComfy API endpoints. Filesystem access is limited to output directory. Security documentation is present and comprehensive.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":20,"line_start":20}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":68,"line_start":68}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Token Storage in User Home Directory","locations":[{"file":"SKILL.md","line_end":191,"line_start":191}],"confidence":0.8,"description":"The RunComfy CLI stores the API token at ~/.config/runcomfy/token.json. While this is standard CLI practice and the file is created with mode 0600 (owner-only), accessing the user's home directory is a filesystem risk factor.","confidence_reasoning":"Token storage location is documented with proper permission settings. This is standard CLI practice, not a vulnerability."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":196,"audit_model":"claude","audited_at":"2026-05-05T08:55:30.517+00:00","created_at":"2026-05-05T13:38:58.805905+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}