{"data":{"skill":{"slug":"bertona88-commit-chat-push","name":"commit-chat-push","icon":"📦","repo":"https://github.com/bertona88/commit-chat-push/tree/main/","status":"approved","author":"bertona88","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"b11fabed-c42c-4fe3-a491-18459ebac702","skill_id":"156393ed-d74f-43c4-bac8-f7e1eb2e495f","version":6,"content_hash":"v3:8c3e20bba512c392d9b02ee748b18e0b09d4982c:e1df57e87f8c518a630e27394bc76becdd7f615b68049a6ed3251cda4de17683:a0efbf12f83b7a0b68aacb27e6c04256bcbc5346ba330a866f523211f7b7c1bc:736b696c6c732f626572746f6e6138382f636f6d6d69742d636861742d70757368:b65623e6bc7fa13af76b25fbeadad9fd","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static alerts are false positives caused by Markdown backticks, code fences, safe Git inspection commands, and defensive secret-search patterns. Confirmed risks include reading private Codex sessions, permitting raw-session commits, and pushing transcript content to a remote repository. The referenced redaction exporter is missing, so its privacy controls cannot be audited.","remediation":[{"issue":"The security-critical transcript exporter is missing from the audited package.","severity":"high","suggestion":"Include the exporter source and tests. Verify secret redaction, anchored session selection, path handling, and safe output defaults before publication."},{"issue":"The workflow permits raw Codex session logs to be committed after a warning.","severity":"high","suggestion":"Prohibit raw JSONL commits. Export only reviewed Markdown with system instructions, tool output, local paths, and secret patterns removed."},{"issue":"Transcript content is pushed to a remote repository.","severity":"medium","suggestion":"Show the selected remote, staged transcript, and secret-scan result. Require explicit confirmation immediately before push."},{"issue":"Unanchored selection can choose the newest session sharing the repository path.","severity":"medium","suggestion":"Require a fresh unique anchor for every export. Remove automatic newest-session fallback from the publish workflow."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"README.md","line_end":90,"line_start":89},{"file":"README.md","line_end":92,"line_start":91},{"file":"README.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":38,"line_start":31},{"file":"SKILL.md","line_end":42,"line_start":38},{"file":"SKILL.md","line_end":49,"line_start":42},{"file":"SKILL.md","line_end":51,"line_start":49},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":59,"line_start":57},{"file":"SKILL.md","line_end":62,"line_start":59},{"file":"SKILL.md","line_end":66,"line_start":62},{"file":"SKILL.md","line_end":67,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":77,"line_start":73},{"file":"SKILL.md","line_end":80,"line_start":77},{"file":"SKILL.md","line_end":81,"line_start":80},{"file":"SKILL.md","line_end":86,"line_start":81},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":94,"line_start":92},{"file":"SKILL.md","line_end":96,"line_start":94},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":98,"line_start":97},{"file":"SKILL.md","line_end":99,"line_start":98},{"file":"SKILL.md","line_end":100,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":49,"line_start":42}]},{"factor":"network","evidence":[{"file":"README.md","line_end":21,"line_start":21}]},{"factor":"filesystem","evidence":[{"file":"README.md","line_end":3,"line_start":3},{"file":"README.md","line_end":3,"line_start":3},{"file":"README.md","line_end":20,"line_start":20},{"file":"README.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":93,"line_start":93}]}],"critical_findings":[],"high_findings":[{"title":"Hidden file in home directory","locations":[{"file":"README.md","line_end":3,"line_start":3}],"confidence":0.98,"description":"Commit Chat Push is a Codex skill for shipping code with its implementation provenance. It guides Co","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The description explicitly reads Codex sessions under the hidden home directory and prepares their contents for a repository commit."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":3,"line_start":3}],"confidence":0.98,"description":"description: Commit and push repository changes while also exporting and committing the Codex chat/s","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The trigger description explicitly directs access to Codex sessions under ~/.codex and includes their exported content in a commit."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":62,"line_start":62}],"confidence":0.98,"description":"- Do not commit raw `~/.codex/sessions/*.jsonl` unless the user explicitly asks for raw logs after b","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The workflow permits committing raw session JSONL after a warning. Those files can contain secrets, private prompts, and full tool output."},{"title":"Session Transcript Publication Can Expose Sensitive Data","locations":[{"file":"SKILL.md","line_end":12,"line_start":10},{"file":"SKILL.md","line_end":62,"line_start":53},{"file":"SKILL.md","line_end":82,"line_start":79}],"confidence":0.99,"description":"The workflow exports private Codex session content, adds the transcript to a commit, and pushes it. Redaction is explicitly described as incomplete.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The skill directly combines session export, transcript staging, and git push while warning that sessions can contain secrets and private instructions."}],"medium_findings":[{"title":"Hidden file access","locations":[{"file":"README.md","line_end":3,"line_start":3}],"confidence":0.98,"description":"Commit Chat Push is a Codex skill for shipping code with its implementation provenance. It guides Co","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The advertised workflow accesses private Codex session data under ~/.codex and exports it into source control."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":49,"line_start":42}],"confidence":0.94,"description":"```bash","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The block instructs execution of a Python helper that processes private Codex session data and writes an export. The helper implementation is absent from the audit."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":81,"line_start":80}],"confidence":0.97,"description":"- If the branch already has an upstream, run `git push`.","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The instruction runs git push, which transmits the staged code and transcript to the configured remote repository."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":86,"line_start":81}],"confidence":0.97,"description":"- If it does not and a default remote exists, run `git push -u origin HEAD`.","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The instruction runs git push with upstream creation, causing an external repository mutation and possible transcript disclosure."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":3,"line_start":3}],"confidence":0.98,"description":"description: Commit and push repository changes while also exporting and committing the Codex chat/s","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The advertised workflow reads private session records from the hidden Codex home directory for publication."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":62,"line_start":62}],"confidence":0.98,"description":"- Do not commit raw `~/.codex/sessions/*.jsonl` unless the user explicitly asks for raw logs after b","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The line allows raw ~/.codex session files to enter source control after user confirmation, retaining substantial disclosure risk."},{"title":"Security-Critical Exporter Is Missing From the Audited Package","locations":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":49,"line_start":42},{"file":"README.md","line_end":54,"line_start":37}],"confidence":0.99,"description":"The documentation invokes an exporter as the redaction boundary, but its implementation is absent from the three audited files. Redaction and session selection cannot be verified.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Both documentation files reference scripts/export_codex_session.py, while the audited package contains only .gitignore, README.md, and SKILL.md."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":220,"audit_model":"codex","audited_at":"2026-07-23T11:27:37.934+00:00","created_at":"2026-07-24T09:13:30.573264+00:00","static_findings":[{"id":"sensitive:.gitignore:4:environment-file-access","file":".gitignore","pattern":"Environment file access","snippet":".env","category":"sensitive","line_end":4,"severity":"high","line_start":4},{"id":"sensitive:.gitignore:5:environment-file-access","file":".gitignore","pattern":"Environment file access","snippet":".env.*","category":"sensitive","line_end":5,"severity":"high","line_start":5},{"id":"external_commands:README.md:89:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"|   `-- codex-sessions/","category":"external_commands","line_end":90,"severity":"medium","line_start":89},{"id":"external_commands:README.md:91:ruby-shell-backtick-execution","file":"README.md","pattern":"Ruby/shell backtick execution","snippet":"`-- export_codex_session.py","category":"external_commands","line_end":92,"severity":"medium","line_start":91},{"id":"external_commands:README.md:54:shell-command-substitution","file":"README.md","pattern":"Shell command substitution","snippet":"--repo \"$(pwd)\" \\","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"network:README.md:21:hardcoded-url","file":"README.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/bertona88/commit-chat-push.git \\","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"filesystem:README.md:3:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"Commit Chat Push is a Codex skill for shipping code with its implementation provenance. It guides Co","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:README.md:3:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"Commit Chat Push is a Codex skill for shipping code with its implementation provenance. It guides Co","category":"filesystem","line_end":3,"severity":"medium","line_start":3},{"id":"filesystem:README.md:20:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"mkdir -p \"${CODEX_HOME:-$HOME/.codex}/skills\"","category":"filesystem","line_end":20,"severity":"medium","line_start":20},{"id":"filesystem:README.md:22:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"\"${CODEX_HOME:-$HOME/.codex}/skills/commit-chat-push\"","category":"filesystem","line_end":22,"severity":"medium","line_start":22},{"id":"sensitive:README.md:77:crypto-seed-private-key-mention","file":"README.md","pattern":"Crypto seed/private key mention","snippet":"rg -n \"sk-|ghp_|github_pat_|BEGIN .*PRIVATE KEY|Authorization|Bearer |password|secret|token|api[_-]?","category":"sensitive","line_end":77,"severity":"high","line_start":77},{"id":"blocker:README.md:12:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- Leaves command output disabled by default to avoid re-committing bulky logs or accidentally printe","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Run `git status --short --branch`.","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Run `git remote -v` and `git branch --show-current` when push behavior is not obvious.","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Review `git diff` and staged diff before committing.","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use an existing repo convention for transcripts if one exists, such as `docs/codex-sessions/`, `co","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Otherwise use `docs/codex-sessions/`.","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":38,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":42,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":49,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":51,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If `--require-anchor` fails, wait briefly and rerun with the same marker. If it still fails, inspe","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":59,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":62,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Do not commit raw `~/.codex/sessions/*.jsonl` unless the user explicitly asks for raw logs after b","category":"external_commands","line_end":66,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Prefer explicit pathspecs over `git add .` when the worktree has unrelated changes.","category":"external_commands","line_end":67,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Confirm with `git diff --cached --stat` and `git diff --cached`.","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":77,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the branch already has an upstream, run `git push`.","category":"external_commands","line_end":81,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If it does not and a default remote exists, run `git push -u origin HEAD`.","category":"external_commands","line_end":86,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Prefer anchor-based selection. The marker command above finishes before export, so the JSONL for the","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Without an anchor, `export_codex_session.py` selects the newest Codex JSONL session whose `session_m","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":94,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":96,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--output-dir PATH`: write a generated Markdown filename in `PATH`.","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--output PATH`: write to an exact Markdown path.","category":"external_commands","line_end":98,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--session PATH`: export a specific JSONL session.","category":"external_commands","line_end":99,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--anchor TEXT`: prefer a session JSONL containing exact marker text.","category":"external_commands","line_end":100,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--require-anchor`: fail unless the selected session contains `--anchor`.","category":"external_commands","line_end":100,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--tool-output none|brief|full`: control command output included in the transcript. Default is `no","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `--include-local-paths`: include full local source paths in metadata. By default, home paths are s","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:44:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"--repo \"$(pwd)\" \\","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:42:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":49,"severity":"medium","line_start":42},{"id":"filesystem:SKILL.md:3:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"description: Commit and push repository changes while also exporting and committing the Codex chat/s","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"filesystem:SKILL.md:62:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"- Do not commit raw `~/.codex/sessions/*.jsonl` unless the user explicitly asks for raw logs after b","category":"filesystem","line_end":62,"severity":"high","line_start":62},{"id":"filesystem:SKILL.md:3:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"description: Commit and push repository changes while also exporting and committing the Codex chat/s","category":"filesystem","line_end":3,"severity":"medium","line_start":3},{"id":"filesystem:SKILL.md:43:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"python3 \"${CODEX_HOME:-$HOME/.codex}/skills/commit-chat-push/scripts/export_codex_session.py\" \\","category":"filesystem","line_end":43,"severity":"medium","line_start":43},{"id":"filesystem:SKILL.md:62:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- Do not commit raw `~/.codex/sessions/*.jsonl` unless the user explicitly asks for raw logs after b","category":"filesystem","line_end":62,"severity":"medium","line_start":62},{"id":"filesystem:SKILL.md:93:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"python3 \"${CODEX_HOME:-$HOME/.codex}/skills/commit-chat-push/scripts/export_codex_session.py\" --help","category":"filesystem","line_end":93,"severity":"medium","line_start":93},{"id":"sensitive:SKILL.md:58:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"rg -n \"sk-|ghp_|github_pat_|BEGIN .*PRIVATE KEY|Authorization|Bearer |password|secret|token|api[_-]?","category":"sensitive","line_end":58,"severity":"high","line_start":58}],"finding_verdicts":[{"id":"sensitive:.gitignore:4:environment-file-access","reason":"The line excludes .env from version control. It does not read, expose, or transmit an environment file.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:.gitignore:5:environment-file-access","reason":"The wildcard excludes environment files from version control. This is a protective ignore rule, not sensitive-file access.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:README.md:89:ruby-shell-backtick-execution","reason":"The backtick is an ASCII repository-tree branch inside a text code block. It is not executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:README.md:91:ruby-shell-backtick-execution","reason":"The backtick is an ASCII repository-tree branch before a filename. No shell or Ruby execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:README.md:54:shell-command-substitution","reason":"The quoted substitution runs only the fixed pwd command to pass the current repository path. No untrusted command text is evaluated.","verdict":"false_positive","confidence":0.97},{"id":"network:README.md:21:hardcoded-url","reason":"The URL is the declared public GitHub source used in a transparent installation command. It is not an exfiltration endpoint.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:3:hidden-file-in-home-directory","reason":"The description explicitly reads Codex sessions under the hidden home directory and prepares their contents for a repository commit.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"filesystem:README.md:3:hidden-file-access","reason":"The advertised workflow accesses private Codex session data under ~/.codex and exports it into source control.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"filesystem:README.md:20:hidden-file-access","reason":"This command creates the standard Codex skills installation directory. It does not access session logs or other private content.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:22:hidden-file-access","reason":"This is the destination path for installing the named skill under CODEX_HOME. The path use is expected and narrowly scoped.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:README.md:77:crypto-seed-private-key-mention","reason":"Private-key and token terms appear only in an rg pattern that searches exported transcripts for secrets before committing them.","verdict":"false_positive","confidence":0.99},{"id":"blocker:README.md:12:system-reconnaissance","reason":"The line states that command output is disabled to reduce secret exposure. It performs no reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"This is Markdown inline code for a fixed, read-only git status command. It contains no dynamic input or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The fixed git remote and branch commands inspect repository configuration. They do not mutate files or evaluate user-controlled shell text.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The inline git diff reference is a read-only review step. Markdown backticks were misclassified as command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The backticked values are example transcript directories. They are paths, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticked value is the documented default output directory. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The code block runs fixed Python that prints a random anchor marker. It does not consume untrusted input or access sensitive files.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The detected text is the closing Markdown fence and surrounding instructions. It is not executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The block instructs execution of a Python helper that processes private Codex session data and writes an export. The helper implementation is absent from the audit.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The location contains a closing code fence and failure guidance. It does not introduce dynamic shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"Inline backticks identify a command option and an example session path. The text does not execute Ruby or interpolate commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The block contains a fixed rg safety scan for secret indicators. It is defensive and does not execute matched transcript content.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The line is a Markdown fence following the defensive secret scan. It has no execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The backticked JSONL path appears in a warning against committing raw sessions. Markdown formatting was misclassified as execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The line warns against broad git add usage and recommends explicit pathspecs. It is protective guidance, not Ruby execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The fixed git diff commands review staged content before publication. They contain no dynamic command construction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"This is the opening fence for a plain-text commit message example. The content is not executable.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"This is a closing Markdown fence. It does not invoke a shell or Ruby interpreter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The instruction runs git push, which transmits the staged code and transcript to the configured remote repository.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The instruction runs git push with upstream creation, causing an external repository mutation and possible transcript disclosure.","verdict":"confirmed","severity":"medium","confidence":0.97},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"Backticks format option names and a script filename in explanatory prose. The line does not execute them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"Backticks format a script name, metadata field, and option in prose. No shell execution appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The code block invokes a fixed help command for the installed helper. It has no untrusted arguments and requests documentation only.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The detected line is the closing Markdown fence for the help command. It is not executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"Backticks format an exporter option and placeholder path in documentation. No command runs at this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"Backticks format an exporter option and placeholder output path. They do not represent Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"Backticks format an exporter option and placeholder session path. This is documentation, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"Backticks format the anchor option in documentation. The line does not invoke or interpolate a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"Backticks format two related option names. No shell or Ruby execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"Backticks format accepted option values and safety advice. This is not executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"Backticks format an option and a shortened home-path symbol. The line is explanatory documentation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:shell-command-substitution","reason":"The substitution runs only the fixed pwd command and is quoted as one repository-path argument. It does not evaluate user-provided command text.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:42:template-literal-with-command-substitution","reason":"This is a Bash code fence, not a language template literal. Its only command substitution is the fixed, quoted pwd call.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:3:hidden-file-in-home-directory","reason":"The trigger description explicitly directs access to Codex sessions under ~/.codex and includes their exported content in a commit.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"filesystem:SKILL.md:62:hidden-file-in-home-directory","reason":"The workflow permits committing raw session JSONL after a warning. Those files can contain secrets, private prompts, and full tool output.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"filesystem:SKILL.md:3:hidden-file-access","reason":"The advertised workflow reads private session records from the hidden Codex home directory for publication.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"filesystem:SKILL.md:43:hidden-file-access","reason":"The hidden path identifies the installed skill helper under CODEX_HOME. It does not itself target private session records.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:62:hidden-file-access","reason":"The line allows raw ~/.codex session files to enter source control after user confirmation, retaining substantial disclosure risk.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"filesystem:SKILL.md:93:hidden-file-access","reason":"The path points to the installed skill helper and requests its help text. It does not read Codex session content.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:58:crypto-seed-private-key-mention","reason":"Sensitive terms appear only in a defensive rg pattern used to find secrets before a transcript is committed.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Session Transcript Publication Can Expose Sensitive Data","severity":"high","locations":[{"file":"SKILL.md","line_end":12,"line_start":10},{"file":"SKILL.md","line_end":62,"line_start":53},{"file":"SKILL.md","line_end":82,"line_start":79}],"confidence":0.99,"description":"The workflow exports private Codex session content, adds the transcript to a commit, and pushes it. Redaction is explicitly described as incomplete.","confidence_reasoning":"The skill directly combines session export, transcript staging, and git push while warning that sessions can contain secrets and private instructions."},{"title":"Security-Critical Exporter Is Missing From the Audited Package","severity":"medium","locations":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":49,"line_start":42},{"file":"README.md","line_end":54,"line_start":37}],"confidence":0.99,"description":"The documentation invokes an exporter as the redaction boundary, but its implementation is absent from the three audited files. Redaction and session selection cannot be verified.","confidence_reasoning":"Both documentation files reference scripts/export_codex_session.py, while the audited package contains only .gitignore, README.md, and SKILL.md."}],"subject_marketplace_commit_sha":"8c3e20bba512c392d9b02ee748b18e0b09d4982c","subject_content_hash":"e1df57e87f8c518a630e27394bc76becdd7f615b68049a6ed3251cda4de17683","subject_tree_hash":"a0efbf12f83b7a0b68aacb27e6c04256bcbc5346ba330a866f523211f7b7c1bc","subject_plugin_path":"skills/bertona88/commit-chat-push","audit_payload_hash":"b65623e6bc7fa13af76b25fbeadad9fd","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"8c3e20bba512c392d9b02ee748b18e0b09d4982c","contentHash":"e1df57e87f8c518a630e27394bc76becdd7f615b68049a6ed3251cda4de17683","treeHash":"a0efbf12f83b7a0b68aacb27e6c04256bcbc5346ba330a866f523211f7b7c1bc","pluginPath":"skills/bertona88/commit-chat-push","auditPayloadHash":"b65623e6bc7fa13af76b25fbeadad9fd"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/bertona88-commit-chat-push/audits/6/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":9,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}