{"data":{"skill":{"slug":"artemxtech-bases","name":"bases","icon":"📦","repo":"https://github.com/ArtemXTech/personal-os-skills/tree/main/skills/bases","status":"approved","author":"ArtemXTech","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"60f49177-8bd3-4a32-9f75-1cfd2e9039b1","skill_id":"2ab15102-d09d-4d23-939f-be67f0071c52","version":7,"content_hash":"97a9ebb0b5906b7982af5de5650aeb8e","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static command and network findings are mostly true positives in documentation examples that call a local Obsidian RPC service with curl and process results with jq. The weak cryptographic algorithm finding is a false positive from the RPC description, and no prompt injection or malicious exfiltration intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":20,"line_start":17},{"file":"SKILL.md","line_end":26,"line_start":23},{"file":"SKILL.md","line_end":32,"line_start":29},{"file":"SKILL.md","line_end":60,"line_start":54}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":64,"line_start":64}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Local RPC Commands Can Read Obsidian Vault Data","locations":[{"file":"SKILL.md","line_end":20,"line_start":17},{"file":"SKILL.md","line_end":26,"line_start":23},{"file":"SKILL.md","line_end":32,"line_start":29}],"confidence":0.86,"description":"TRUE POSITIVE: The skill documents curl commands that query a local Obsidian Bases Query RPC endpoint. This is legitimate for the skill purpose, but it can expose structured note metadata and frontmatter to the AI session when a user runs the commands.","confidence_reasoning":"The documented commands directly call a local RPC endpoint and return Obsidian base data. The intent is functional rather than malicious, but the data access risk is real."},{"title":"Shell Pipeline Examples Require User Review","locations":[{"file":"SKILL.md","line_end":60,"line_start":54}],"confidence":0.78,"description":"TRUE POSITIVE: The skill includes jq command examples for extracting fields from RPC responses. The examples are simple and fixed, but agents should not run shell commands against private vault data without user consent.","confidence_reasoning":"The shell examples are visible and limited to jq filters. Risk depends on user authorization and the sensitivity of local Obsidian data."}],"low_findings":[{"title":"Loopback Network Endpoint Is Expected","locations":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":30,"line_start":30}],"confidence":0.91,"description":"FALSE POSITIVE FOR EXTERNAL NETWORK RISK: The hardcoded URL and IP address point to 127.0.0.1 for a local Obsidian plugin. No evidence found of outbound third-party exfiltration.","confidence_reasoning":"Every detected RPC URL uses 127.0.0.1, which is loopback. The only non-local URL is the installation link for the required plugin."},{"title":"Weak Cryptography Finding Is Not Supported","locations":[{"file":"SKILL.md","line_end":3,"line_start":3}],"confidence":0.96,"description":"FALSE POSITIVE: The line describes RPC usage and does not reference a weak hash, cipher, or cryptographic operation. No evidence found of cryptographic code.","confidence_reasoning":"Line 3 is plain metadata describing the Bases Query plugin RPC interface. There is no cryptographic algorithm or security primitive in the file."},{"title":"Plugin Installation Link Requires Source Trust","locations":[{"file":"SKILL.md","line_end":64,"line_start":64}],"confidence":0.74,"description":"TRUE POSITIVE LOW RISK: The skill links to a GitHub repository for installation through BRAT. This is normal for Obsidian community plugins, but users should review the plugin before installing it.","confidence_reasoning":"The GitHub URL is clearly an installation reference, not an automatic download or execution step. Supply-chain risk remains because it depends on an external plugin."}],"dangerous_patterns":[{"title":"Documented curl POST Requests","locations":[{"file":"SKILL.md","line_end":20,"line_start":17},{"file":"SKILL.md","line_end":26,"line_start":23},{"file":"SKILL.md","line_end":32,"line_start":29}],"confidence":0.88,"description":"The skill instructs use of curl POST requests to a local RPC endpoint. This is intentional but should be treated as a permissioned data access operation.","confidence_reasoning":"The command pattern is explicit and repeated. The endpoint is local, which reduces but does not remove privacy risk."},{"title":"Localhost RPC Endpoint","locations":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":30,"line_start":30}],"confidence":0.9,"description":"The skill hardcodes a localhost RPC endpoint at 127.0.0.1:27125. This limits network scope to the local machine but can access local vault data through the plugin.","confidence_reasoning":"The hardcoded loopback endpoint is clearly present. The security impact depends on what the installed Obsidian plugin exposes."}],"files_scanned":1,"total_lines":65,"audit_model":"codex","audited_at":"2026-06-28T10:21:20.32+00:00","created_at":"2026-06-28T11:02:03.161836+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}