{"data":{"skill":{"slug":"aykahshi-copilot-flow","name":"copilot-flow","icon":"📦","repo":"https://github.com/Aykahshi/copilot-mcp-tool/tree/main/plugins/copilot-flow/skills/copilot-flow-integration","status":"approved","author":"Aykahshi","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"8ec4d905-abbe-46ee-a7d5-2d32026e4520","skill_id":"0bf1cc21-d8f6-486e-b7e6-040df41a5019","version":7,"content_hash":"d9f40cb7608ccbd62fbdc15864145c66","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported many high-risk patterns, but the reviewed file contains Markdown documentation rather than executable code. The backtick, weak cryptography, and reconnaissance detections are false positives; the real concerns are repository file modification, external Copilot MCP collaboration, and possible interaction history retention.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":41,"line_start":39},{"file":"SKILL.md","line_end":51,"line_start":49},{"file":"SKILL.md","line_end":102,"line_start":98},{"file":"SKILL.md","line_end":151,"line_start":151}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":88,"line_start":85},{"file":"SKILL.md","line_end":96,"line_start":94},{"file":"SKILL.md","line_end":124,"line_start":119},{"file":"SKILL.md","line_end":147,"line_start":143},{"file":"SKILL.md","line_end":153,"line_start":153}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"External AI Collaboration May Share Project Context","verdict":"TRUE_POSITIVE_SEMANTIC_RISK","locations":[{"file":"SKILL.md","line_end":41,"line_start":39},{"file":"SKILL.md","line_end":51,"line_start":49},{"file":"SKILL.md","line_end":102,"line_start":98},{"file":"SKILL.md","line_end":151,"line_start":151}],"confidence":0.78,"description":"The workflow delegates design and review stages to Copilot through MCP. This is core functionality, but it may expose requirements, code details, or review context to an external assistant depending on the MCP configuration.","confidence_reasoning":"The file explicitly assigns design and review responsibilities to Copilot via MCP. No malicious endpoint is present, so the concern is privacy and data handling rather than confirmed exfiltration."},{"title":"Workflow Writes State, Reports, Source Files, and Delivery Artifacts","verdict":"TRUE_POSITIVE_SEMANTIC_RISK","locations":[{"file":"SKILL.md","line_end":88,"line_start":85},{"file":"SKILL.md","line_end":96,"line_start":94},{"file":"SKILL.md","line_end":124,"line_start":119},{"file":"SKILL.md","line_end":147,"line_start":143},{"file":"SKILL.md","line_end":153,"line_start":153}],"confidence":0.84,"description":"The skill instructs agents to maintain workflow state, produce reports, write source files, and create delivery output. This is legitimate for a development workflow, but users should review changes before applying them.","confidence_reasoning":"Multiple documented workflow outputs require file system writes. The behavior matches the skill purpose and does not show destructive intent."}],"low_findings":[{"title":"Static Command Execution Matches Are Markdown False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":65,"line_start":63},{"file":"SKILL.md","line_end":81,"line_start":77},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":109,"line_start":107},{"file":"SKILL.md","line_end":124,"line_start":120}],"confidence":0.93,"description":"The reported Ruby or shell backtick findings map to Markdown inline code, code fences, output filenames, and slash command examples. No executable script, shell invocation, or command interpolation was found in SKILL.md.","confidence_reasoning":"Line review shows documentation examples and filenames inside Markdown formatting. There is no Ruby code, shell code, or executable wrapper in the scanned file."},{"title":"Static Weak Cryptography Matches Are Text False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":25,"line_start":24},{"file":"SKILL.md","line_end":41,"line_start":33},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":156,"line_start":151}],"confidence":0.9,"description":"The high-risk weak cryptography detections appear to match ordinary documentation text such as design, workflow descriptions, or .md filenames. No cryptographic API, hashing function, or encryption operation was found.","confidence_reasoning":"The reviewed lines contain prose and Markdown output names, not code using MD5, DES, RC4, or similar weak algorithms. The scanner likely matched substrings in natural language."},{"title":"Static Network Reconnaissance Match Is a Documentation False Positive","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":86,"line_start":86}],"confidence":0.88,"description":"The low-risk network reconnaissance finding points to workflow state documentation. No scanning command, host discovery logic, or network probing instruction was found at that location.","confidence_reasoning":"Line 86 documents a local workflow-state file path. It does not include a reconnaissance tool name or a network operation."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":156,"audit_model":"codex","audited_at":"2026-06-28T12:49:29.951+00:00","created_at":"2026-06-28T14:22:51.955382+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}