{"data":{"skill":{"slug":"ariegoldkin-testing-strategy-builder","name":"testing-strategy-builder","icon":"📦","repo":"https://github.com/ArieGoldkin/ai-agent-hub/tree/main/skills/testing-strategy-builder","status":"approved","author":"AI Agent Hub","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"47613e5b-1ffc-477d-b582-329339c407d4","skill_id":"de6d6047-a0e1-4911-9970-7b6add9e5668","version":6,"content_hash":"6a48920df407f92efd6ddd99ef4caae0","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged many shell, network, filesystem, and weak-crypto patterns, but reviewed evidence shows they are Markdown examples, templates, and testing guidance rather than executable skill logic. No prompt-injection language, data exfiltration intent, or malicious automation was found in the reviewed files. The skill is suitable for publication with low risk because users may copy commands or sample tests into their own projects.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":50,"line_start":36},{"file":"SKILL.md","line_end":89,"line_start":75},{"file":"SKILL.md","line_end":330,"line_start":304},{"file":"references/code-examples.md","line_end":40,"line_start":9},{"file":"templates/test-case-template.md","line_end":158,"line_start":122},{"file":"templates/test-plan-template.md","line_end":313,"line_start":313}]},{"factor":"network","evidence":[{"file":"references/code-examples.md","line_end":92,"line_start":92},{"file":"references/code-examples.md","line_end":112,"line_start":112},{"file":"references/code-examples.md","line_end":183,"line_start":167},{"file":"references/code-examples.md","line_end":183,"line_start":183}]},{"factor":"filesystem","evidence":[{"file":"references/code-examples.md","line_end":254,"line_start":254}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"External Command Patterns Are Documentation Examples","locations":[{"file":"SKILL.md","line_end":50,"line_start":36},{"file":"SKILL.md","line_end":89,"line_start":75},{"file":"SKILL.md","line_end":330,"line_start":304},{"file":"templates/test-plan-template.md","line_end":313,"line_start":313}],"confidence":0.94,"description":"Verdict: FALSE_POSITIVE. The flagged command patterns appear in Markdown installation commands, verification commands, CI examples, and code fences. They are not executed by the skill and do not include user-controlled command construction.","confidence_reasoning":"The cited locations are visible Markdown guidance or fenced examples. No executable script file or dynamic command invocation was found in these reviewed locations."},{"title":"Network Patterns Are Sample Test Requests","locations":[{"file":"references/code-examples.md","line_end":92,"line_start":92},{"file":"references/code-examples.md","line_end":112,"line_start":112},{"file":"references/code-examples.md","line_end":183,"line_start":167}],"confidence":0.91,"description":"Verdict: FALSE_POSITIVE. The HTTP client and URL findings are example API tests and a k6 load-test sample. The skill does not send data externally or configure a real destination for exfiltration.","confidence_reasoning":"The reviewed network references are inside test examples and target local app routes or example.com. There is no evidence of credential collection or outbound calls by the skill itself."},{"title":"Filesystem And Weak-Crypto Alerts Lack Risk Context","locations":[{"file":"references/code-examples.md","line_end":254,"line_start":254},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"templates/test-plan-template.md","line_end":180,"line_start":180},{"file":"templates/test-case-template.md","line_end":23,"line_start":23}],"confidence":0.88,"description":"Verdict: FALSE_POSITIVE. The path traversal finding is a Jest mock import in a code example, and weak-crypto alerts occur at general testing text or sample data locations. No filesystem access routine or cryptographic implementation was found at the cited locations.","confidence_reasoning":"The cited path is a relative mock path inside an illustrative test. Reviewed weak-crypto locations do not contain crypto API use, key handling, or hashing implementation."}],"dangerous_patterns":[],"files_scanned":5,"total_lines":1675,"audit_model":"codex","audited_at":"2026-06-28T10:37:20.866+00:00","created_at":"2026-06-28T11:02:00.248191+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}