{"data":{"skill":{"slug":"avdlee-swift-concurrency","name":"swift-concurrency","icon":"📦","repo":"https://github.com/AvdLee/Swift-Concurrency-Agent-Skill/tree/main/swift-concurrency/","status":"approved","author":"AvdLee","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"63508388-30a7-4dc2-bb93-c681ee5a8240","skill_id":"b2a36184-3672-4561-9c62-2af12de2fd68","version":6,"content_hash":"71318810b218ce26fdafaf50b47ccb9a","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported many command, network, storage, reconnaissance, and weak-crypto patterns. Manual review found these are markdown code fences, Swift code examples, course links, and Swift terminology, with no executable scripts or prompt injection evidence. The skill is publishable with low risk because it is documentation-heavy and includes external educational links and sample network code.","remediation":[],"risk_factor_evidence":[],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Command execution detections are markdown false positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":17,"line_start":14},{"file":"references/actors.md","line_end":17,"line_start":9},{"file":"references/async-await-basics.md","line_end":17,"line_start":7}],"confidence":0.96,"description":"Static analysis flagged many backticks as Ruby or shell execution. The reviewed locations are markdown inline code and Swift code fences that describe concurrency APIs, not executable skill behavior.","confidence_reasoning":"The cited content is markdown documentation containing Swift examples and inline API names. No executable script files or command invocation logic were found in the reviewed skill structure."},{"title":"Network detections are educational links and sample code","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":230,"line_start":230},{"file":"references/async-await-basics.md","line_end":158,"line_start":129},{"file":"references/testing.md","line_end":231,"line_start":229}],"confidence":0.92,"description":"The network hits point to course links, package references, and Swift URLSession examples. They do not cause the skill itself to make network requests or exfiltrate data.","confidence_reasoning":"The reviewed URLs are visible references or placeholder example endpoints. They are not hidden destinations and are not paired with credential access or automatic execution."},{"title":"Browser storage detection is a Swift testing example","verdict":"FALSE_POSITIVE","locations":[{"file":"references/testing.md","line_end":159,"line_start":156}],"confidence":0.95,"description":"The sensitive storage hit is a TaskLocal database example in Swift Testing documentation. It is not browser local storage, cookie access, or credential persistence.","confidence_reasoning":"The exact lines define a Swift @TaskLocal value for test scoping. This is unrelated to browser storage APIs and does not access user secrets."},{"title":"Blocker categories map to Swift terminology, not malicious behavior","verdict":"FALSE_POSITIVE","locations":[{"file":"references/core-data.md","line_end":25,"line_start":23},{"file":"references/migration.md","line_end":92,"line_start":87},{"file":"references/performance.md","line_end":351,"line_start":349}],"confidence":0.88,"description":"The weak-crypto and reconnaissance labels appear to match unrelated Swift text such as @unchecked Sendable guidance, migration prose, Instruments checks, or fetch examples. No evidence of cryptographic misuse, host reconnaissance, or network scanning was found.","confidence_reasoning":"The static categories do not match the semantic context of the reviewed lines. Confidence is high because the files are educational markdown, but the scanner output is broad and noisy."}],"dangerous_patterns":[],"files_scanned":13,"total_lines":6356,"audit_model":"codex","audited_at":"2026-06-28T11:39:06.326+00:00","created_at":"2026-06-28T12:41:21.969394+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":4,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}