{"data":{"skill":{"slug":"andresnaza-roadmap-planning-expert","name":"Roadmap Planning Expert","icon":"📦","repo":"https://github.com/AndresNaza/claude-plugins/tree/main/roadmap-planner/skills/roadmap-planning","status":"approved","author":"AndresNaza","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"0ddcee35-5cbe-437c-a4b2-5094809ace29","skill_id":"fd429f1e-b96d-4e56-a70b-91fcda71c371","version":11,"content_hash":"v3:80999bf530a7874d7bedf8ce202001ecb4c4f5e0:bc97ee7a6f33f421969764bbcda2f2a15cb2174254ab806cbe33b0f1fcfe5181:6e262b168135316567ab5ce06c049735dd7942f5d9e999b798905d0aeef9cd72:736b696c6c732f616e647265736e617a612f726f61646d61702d706c616e6e696e672d657870657274:518f8424601dc3ee0a0ff65cbaccefe9","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 18 static findings are false positives caused by Markdown backticks in diagrams, file names, and documented slash commands. The skill contains planning guidance only; no executable shell or Ruby code, network instructions, or prompt-injection language was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":60,"line_start":51},{"file":"SKILL.md","line_end":64,"line_start":60},{"file":"SKILL.md","line_end":65,"line_start":64},{"file":"SKILL.md","line_end":66,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":66},{"file":"SKILL.md","line_end":68,"line_start":67},{"file":"SKILL.md","line_end":69,"line_start":68},{"file":"SKILL.md","line_end":74,"line_start":69},{"file":"SKILL.md","line_end":75,"line_start":74},{"file":"SKILL.md","line_end":76,"line_start":75},{"file":"SKILL.md","line_end":77,"line_start":76},{"file":"SKILL.md","line_end":78,"line_start":77},{"file":"SKILL.md","line_end":81,"line_start":78},{"file":"SKILL.md","line_end":82,"line_start":81},{"file":"SKILL.md","line_end":83,"line_start":82},{"file":"SKILL.md","line_end":86,"line_start":83},{"file":"SKILL.md","line_end":101,"line_start":86},{"file":"SKILL.md","line_end":102,"line_start":101}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":107,"audit_model":"claude","audited_at":"2026-07-18T10:04:21.333+00:00","created_at":"2026-07-19T01:52:03.051261+00:00","static_findings":[{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":60,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":64,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All roadmap files in `.roadmap/`:","category":"external_commands","line_end":65,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `config.json` - Team configuration","category":"external_commands","line_end":66,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `quarters/` - Quarterly roadmaps","category":"external_commands","line_end":67,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `epics/` - Epic files with milestones","category":"external_commands","line_end":68,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `sprints/` - Sprint plans","category":"external_commands","line_end":69,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `templates/` - File templates","category":"external_commands","line_end":74,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:init` - Initialize roadmap structure","category":"external_commands","line_end":75,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:team` - Configure team","category":"external_commands","line_end":76,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:plan-quarter` - Plan quarterly epics (collaborative)","category":"external_commands","line_end":77,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:plan-epic` - Break epic into milestones (collaborative)","category":"external_commands","line_end":78,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:plan-sprint` - Allocate milestones to sprint (collaborative)","category":"external_commands","line_end":81,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:status` - View progress at any level","category":"external_commands","line_end":82,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:update` - Mark milestones done","category":"external_commands","line_end":83,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:capacity` - Show capacity calculations","category":"external_commands","line_end":86,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/roadmap-planner:schedule` - Assign start/end dates to milestones for Gantt visualization","category":"external_commands","line_end":101,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `/clickup-sync:push` - Push epics and milestones","category":"external_commands","line_end":102,"severity":"medium","line_start":101}],"finding_verdicts":[{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"Lines 51-60 are a Markdown code fence containing a planning hierarchy, not executable Ruby or shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"Line 60 closes the Markdown diagram fence and is not an execution instruction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backticks format a local directory name in prose; no command is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks format a configuration filename in documentation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backticks format a local roadmap directory in documentation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticks format a local epic directory in documentation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backticks format a local sprint directory in documentation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The backticks format a local template directory in documentation, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"This is a documented plugin slash command identifier, not a Ruby or shell backtick execution expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"This is a documented plugin slash command identifier, not a Ruby or shell backtick execution expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"This is a documented collaborative planning command, not a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"This is a documented collaborative planning command, not a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"This is a documented collaborative planning command, not a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This is a documented plugin slash command identifier, not a Ruby or shell backtick execution expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"This is a documented plugin slash command identifier, not a Ruby or shell backtick execution expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"This is a documented plugin slash command identifier, not a Ruby or shell backtick execution expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"This is a documented scheduling command identifier, not a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"This is a documented ClickUp integration command identifier, not a Ruby or shell backtick execution expression.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":"80999bf530a7874d7bedf8ce202001ecb4c4f5e0","subject_content_hash":"bc97ee7a6f33f421969764bbcda2f2a15cb2174254ab806cbe33b0f1fcfe5181","subject_tree_hash":"6e262b168135316567ab5ce06c049735dd7942f5d9e999b798905d0aeef9cd72","subject_plugin_path":"skills/andresnaza/roadmap-planning-expert","audit_payload_hash":"518f8424601dc3ee0a0ff65cbaccefe9","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"80999bf530a7874d7bedf8ce202001ecb4c4f5e0","contentHash":"bc97ee7a6f33f421969764bbcda2f2a15cb2174254ab806cbe33b0f1fcfe5181","treeHash":"6e262b168135316567ab5ce06c049735dd7942f5d9e999b798905d0aeef9cd72","pluginPath":"skills/andresnaza/roadmap-planning-expert","auditPayloadHash":"518f8424601dc3ee0a0ff65cbaccefe9"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/andresnaza-roadmap-planning-expert/audits/11/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}