{"data":{"skill":{"slug":"aykahshi-copilot-mcp-server","name":"copilot-mcp-server","icon":"📦","repo":"https://github.com/Aykahshi/copilot-mcp-tool/tree/main/plugins/copilot-flow/skills/copilot-mcp-server","status":"approved","author":"Aykahshi","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"120529d8-7419-40fd-89ba-5d4392544843","skill_id":"48c3c931-0563-4a0b-b5eb-5377246c60e2","version":9,"content_hash":"v3:bdc4c7c6e1e64de0e81902bd9656da84164bdaf7:23a30f3b516ffb86791df0addd7cbff01f78158f3ec81d85f1056f7aec2e0305:1f3ac3a20a5c9174df6beffb5c47f7f54bf62427b535cd3cf41e05bb495c925c:736b696c6c732f61796b61687368692f636f70696c6f742d6d63702d736572766572:d28756c281d00a20ea5c5ab500ed7b34","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 29 static findings are false positives caused by Markdown code fences, JavaScript template literals, and a descriptive statement about direct access. The skill documents an optional broad tool-authorization setting; enabling it can violate least-privilege controls depending on the configured Copilot MCP server.","remediation":[{"issue":"The ask-copilot example exposes an allowAllTools option that may grant broad downstream tool access.","severity":"medium","suggestion":"Default to false, request explicit user confirmation before enabling it, and document which tools the server exposes."},{"issue":"The security-review example contains an interpolated SQL query.","severity":"low","suggestion":"Label it as intentionally vulnerable and show parameterized queries in the recommended remediation output."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":28,"line_start":21},{"file":"SKILL.md","line_end":33,"line_start":28},{"file":"SKILL.md","line_end":38,"line_start":33},{"file":"SKILL.md","line_end":43,"line_start":38},{"file":"SKILL.md","line_end":48,"line_start":43},{"file":"SKILL.md","line_end":53,"line_start":48},{"file":"SKILL.md","line_end":59,"line_start":53},{"file":"SKILL.md","line_end":64,"line_start":59},{"file":"SKILL.md","line_end":69,"line_start":64},{"file":"SKILL.md","line_end":74,"line_start":69},{"file":"SKILL.md","line_end":79,"line_start":74},{"file":"SKILL.md","line_end":84,"line_start":79},{"file":"SKILL.md","line_end":89,"line_start":84},{"file":"SKILL.md","line_end":96,"line_start":89},{"file":"SKILL.md","line_end":98,"line_start":96},{"file":"SKILL.md","line_end":103,"line_start":98},{"file":"SKILL.md","line_end":107,"line_start":103},{"file":"SKILL.md","line_end":148,"line_start":107},{"file":"SKILL.md","line_end":154,"line_start":148},{"file":"SKILL.md","line_end":157,"line_start":154},{"file":"SKILL.md","line_end":159,"line_start":157},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":165,"line_start":162},{"file":"SKILL.md","line_end":168,"line_start":165},{"file":"SKILL.md","line_end":174,"line_start":168},{"file":"SKILL.md","line_end":177,"line_start":174},{"file":"SKILL.md","line_end":179,"line_start":177},{"file":"SKILL.md","line_end":188,"line_start":185}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Broad Tool Authorization Option","locations":[{"file":"SKILL.md","line_end":27,"line_start":22}],"confidence":0.88,"description":"The ask-copilot interface documents allowAllTools=true, which can grant the downstream Copilot agent access to every available tool. This bypasses least-privilege tool selection when enabled.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The parameter is explicitly documented as allowing all available tools. The actual downstream tool set and approval controls are not documented, so impact depends on the MCP server configuration."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":222,"audit_model":"claude","audited_at":"2026-07-17T10:13:08.258+00:00","created_at":"2026-07-17T15:42:32.143122+00:00","static_findings":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":28,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":33,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":38,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":43,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":48,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":59,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":64,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":69,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":74,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":79,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":84,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":89,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":96,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":98,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":103,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":107,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":148,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":154,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":157,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":159,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"const query = \\`SELECT * FROM users WHERE username = '\\${username}' AND password = '\\${password}'\\`;","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"}`,","category":"external_commands","line_end":165,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":168,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":174,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":177,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":179,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"}`,","category":"external_commands","line_end":188,"severity":"medium","line_start":185},{"id":"blocker:SKILL.md:215:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- This skill provides direct tool access","category":"blocker","line_end":216,"severity":"low","line_start":215}],"finding_verdicts":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"This is a JavaScript template literal inside a deliberately vulnerable SQL example submitted for security review, not a shell or Ruby command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The detection matches Markdown code fences or JavaScript formatting in MCP tool documentation. The cited content does not invoke a shell or execute an external command.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:215:network-reconnaissance","reason":"The cited text only states that the skill offers direct tool access. It contains no host discovery, port scanning, or reconnaissance instruction.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Broad Tool Authorization Option","severity":"medium","locations":[{"file":"SKILL.md","line_end":27,"line_start":22}],"confidence":0.88,"description":"The ask-copilot interface documents allowAllTools=true, which can grant the downstream Copilot agent access to every available tool. This bypasses least-privilege tool selection when enabled.","confidence_reasoning":"The parameter is explicitly documented as allowing all available tools. The actual downstream tool set and approval controls are not documented, so impact depends on the MCP server configuration."}],"subject_marketplace_commit_sha":"bdc4c7c6e1e64de0e81902bd9656da84164bdaf7","subject_content_hash":"23a30f3b516ffb86791df0addd7cbff01f78158f3ec81d85f1056f7aec2e0305","subject_tree_hash":"1f3ac3a20a5c9174df6beffb5c47f7f54bf62427b535cd3cf41e05bb495c925c","subject_plugin_path":"skills/aykahshi/copilot-mcp-server","audit_payload_hash":"d28756c281d00a20ea5c5ab500ed7b34","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bdc4c7c6e1e64de0e81902bd9656da84164bdaf7","contentHash":"23a30f3b516ffb86791df0addd7cbff01f78158f3ec81d85f1056f7aec2e0305","treeHash":"1f3ac3a20a5c9174df6beffb5c47f7f54bf62427b535cd3cf41e05bb495c925c","pluginPath":"skills/aykahshi/copilot-mcp-server","auditPayloadHash":"d28756c281d00a20ea5c5ab500ed7b34"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/aykahshi-copilot-mcp-server/audits/9/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}