{"data":{"skill":{"slug":"aykahshi-copilot-flow","name":"copilot-flow","icon":"📦","repo":"https://github.com/Aykahshi/copilot-mcp-tool/tree/main/plugins/copilot-flow/skills/copilot-flow-integration","status":"approved","author":"Aykahshi","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"2e04a757-dd2f-463d-bd08-11f634cff58f","skill_id":"0bf1cc21-d8f6-486e-b7e6-040df41a5019","version":8,"content_hash":"v2:5ab1d37e83436c6eef84de88573e142b94f2a4ad:3462d6db5799ac2577396c00f937491248e6f3cbb256892217bf2c55d2da2fb8:bb3ab603c22fd124ba847419f832412cd164c67a567864a27270efe8ae35ba71:18a7cefaa4ec5115ccdfa25876f256ac","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 17 static findings are false positives caused by Markdown backticks, fenced prompt examples, and local file path references. The reviewed SKILL.md describes a staged Claude and Copilot development workflow and does not contain executable code, shell commands, network scanning, or prompt injection. No remediation is required for the reported static findings.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":65,"line_start":63},{"file":"SKILL.md","line_end":77,"line_start":65},{"file":"SKILL.md","line_end":81,"line_start":77},{"file":"SKILL.md","line_end":86,"line_start":81},{"file":"SKILL.md","line_end":107,"line_start":86},{"file":"SKILL.md","line_end":109,"line_start":107},{"file":"SKILL.md","line_end":120,"line_start":109},{"file":"SKILL.md","line_end":121,"line_start":120},{"file":"SKILL.md","line_end":123,"line_start":121},{"file":"SKILL.md","line_end":124,"line_start":123},{"file":"SKILL.md","line_end":144,"line_start":124}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":156,"audit_model":"codex","audited_at":"2026-07-05T03:44:58.237+00:00","created_at":"2026-07-05T05:47:39.136218+00:00","static_findings":[{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The workflow is managed through specialized slash commands in the `/commands` directory:","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Output: `analysis-result.md`","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Output: `architecture-design.md`","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Output: Source code files and `implementation-report.md`","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Output: `code-review-report.md`","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":77,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":81,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":86,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `.claude/workflow-state.json` - Current stage and progress","category":"external_commands","line_end":107,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":109,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":120,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `analysis-result.md` - Structured requirements","category":"external_commands","line_end":121,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `architecture-design.md` - System design","category":"external_commands","line_end":123,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `code-review-report.md` - Quality assessment","category":"external_commands","line_end":124,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `delivery/` - Complete package with docs","category":"external_commands","line_end":144,"severity":"medium","line_start":124},{"id":"blocker:SKILL.md:86:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- `.claude/workflow-state.json` - Current stage and progress","category":"blocker","line_end":87,"severity":"low","line_start":86}],"finding_verdicts":[{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The match is inline Markdown around `/commands`, a directory reference in documentation. No shell or Ruby execution is described on this line.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The match is inline Markdown around an output filename. It documents a generated report path and does not execute a command.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The match is inline Markdown around an architecture report filename. It is documentation of expected output, not code execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The match is inline Markdown around an implementation report filename. The line describes workflow output and contains no command runner.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The match is inline Markdown around a code review report filename. It does not invoke Ruby, a shell, or any external process.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The matched backticks are a Markdown code fence around a natural-language usage example. They are not executable Ruby or shell syntax in this context.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown fence delimiters separating example prompts. The surrounding text describes workflow behavior, not command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown block containing slash command examples. This is documentation text and is not executed by the skill file.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown example block. No interpreter, subprocess call, or shell command is present.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The matched backticks quote local workflow state and output file paths. The section documents state management and does not execute external commands.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The matched backticks are a Markdown code fence for an example user request. The content is natural language, not executable shell or Ruby code.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown example block before the workflow description. This is formatting only and has no execution behavior.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The match is inline Markdown around an analysis report filename. It documents expected output and does not run a command.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The match is inline Markdown around an architecture report filename. It is a local output reference, not external command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The match is inline Markdown around a code review report filename. No command execution or shell interpolation is present.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The match is inline Markdown around a delivery directory path. It describes output organization and contains no executable command.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:86:network-reconnaissance","reason":"The referenced lines list a local workflow state file and stage outputs. There is no network target, scanning behavior, or reconnaissance instruction.","verdict":"false_positive","confidence":0.94}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}