{"data":{"skill":{"slug":"caopulan-bark-notify","name":"bark-notify","icon":"📦","repo":"https://github.com/caopulan/Notification-Skill/tree/main/bark-notify","status":"approved","author":"caopulan","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"3a25b9ca-174c-4c68-a6e0-64f92b80d3b8","skill_id":"f6ae5791-096e-4494-9f58-9cff714ded5b","version":6,"content_hash":"6a38a16c565b2c9c980490f449fb3a60","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"AI review did not confirm malicious intent or prompt injection. The critical static heuristic is explained by the skill purpose: it runs a local helper, reads notification configuration, and sends a Bark push request. Publish with a warning because task summaries and the Bark key can leave the local environment.","remediation":[],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"scripts/send_bark_notification.py","line_end":1,"line_start":1},{"file":"SKILL.md","line_end":51,"line_start":45}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":20,"line_start":19},{"file":"scripts/send_bark_notification.py","line_end":129,"line_start":118}]},{"factor":"env_access","evidence":[{"file":"scripts/send_bark_notification.py","line_end":88,"line_start":86}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":51,"line_start":43}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"scripts/send_bark_notification.py","line_end":64,"line_start":50}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Task Summary Sent to External Push Service","locations":[{"file":"scripts/send_bark_notification.py","line_end":119,"line_start":109},{"file":"scripts/send_bark_notification.py","line_end":129,"line_start":127}],"confidence":0.86,"description":"TRUE POSITIVE. The helper builds a notification body from machine name, project name, status, and summary, then posts it to the Bark endpoint. This is the intended feature, but summaries can leak sensitive task details if the caller includes secrets. Confidence: 0.86.","confidence_reasoning":"The network request and payload construction are explicit, but the behavior is legitimate for a notification skill when users avoid sensitive content."},{"title":"Dry Run Can Print Bark Key","locations":[{"file":"scripts/send_bark_notification.py","line_end":123,"line_start":118}],"confidence":0.93,"description":"TRUE POSITIVE. The Bark key is embedded in the URL path, and dry-run mode prints the full POST URL. Terminal logs or copied output could expose the notification token. Confidence: 0.93.","confidence_reasoning":"The code directly constructs the URL with CODEX_BARK_KEY and prints that URL during dry-run execution."},{"title":"Environment Variables Control Notification Credentials and Endpoint","locations":[{"file":"scripts/send_bark_notification.py","line_end":88,"line_start":86},{"file":"scripts/send_bark_notification.py","line_end":119,"line_start":118}],"confidence":0.78,"description":"TRUE POSITIVE with legitimate context. The script reads CODEX_MACHINE_NAME, CODEX_BARK_KEY, and CODEX_BARK_BASE_URL from the environment. This is normal configuration, but a changed base URL can redirect notification contents. Confidence: 0.78.","confidence_reasoning":"The environment access is explicit and necessary, while the base URL override creates a bounded but real data-routing risk."}],"low_findings":[{"title":"Documented Shell Command Invokes Local Helper Script","locations":[{"file":"SKILL.md","line_end":51,"line_start":43}],"confidence":0.95,"description":"FALSE POSITIVE for command injection. The Markdown shows a fixed python3 command for the installed helper script with placeholder arguments. I did not find evidence of untrusted input being interpolated into a shell command by the skill code. Confidence: 0.95.","confidence_reasoning":"The flagged command text is documentation, and the Python script uses argparse rather than shell evaluation."},{"title":"Local Project Metadata Read From AGENTS.md","locations":[{"file":"scripts/send_bark_notification.py","line_end":64,"line_start":50},{"file":"scripts/send_bark_notification.py","line_end":115,"line_start":107}],"confidence":0.82,"description":"TRUE POSITIVE with low severity. The helper searches the current directory and parent directories for AGENTS.md and reads it to extract a project name. This is limited filesystem access and does not exfiltrate file contents except the derived project name in the notification body. Confidence: 0.82.","confidence_reasoning":"The file read is explicit and narrowly scoped to AGENTS.md, with only a parsed name included in the notification."},{"title":"Static Heuristic Findings Mostly Dismissed","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"scripts/send_bark_notification.py","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":51,"line_start":45}],"confidence":0.98,"description":"FALSE POSITIVE. The weak cryptography detections point to descriptive text, not cryptographic code. The path traversal and hidden-file detections are Markdown examples for ~/.codex and placeholder ellipses, not runtime traversal logic. Confidence: 0.98.","confidence_reasoning":"The cited lines are human-readable descriptions or usage examples, and no weak cryptographic primitive or path traversal operation appears there."}],"dangerous_patterns":[{"title":"Task Summary Sent to External Push Service","locations":[{"file":"scripts/send_bark_notification.py","line_end":119,"line_start":109},{"file":"scripts/send_bark_notification.py","line_end":129,"line_start":127}],"confidence":0.86,"description":"TRUE POSITIVE. The helper builds a notification body from machine name, project name, status, and summary, then posts it to the Bark endpoint. This is the intended feature, but summaries can leak sensitive task details if the caller includes secrets. Confidence: 0.86.","confidence_reasoning":"The network request and payload construction are explicit, but the behavior is legitimate for a notification skill when users avoid sensitive content."},{"title":"Dry Run Can Print Bark Key","locations":[{"file":"scripts/send_bark_notification.py","line_end":123,"line_start":118}],"confidence":0.93,"description":"TRUE POSITIVE. The Bark key is embedded in the URL path, and dry-run mode prints the full POST URL. Terminal logs or copied output could expose the notification token. Confidence: 0.93.","confidence_reasoning":"The code directly constructs the URL with CODEX_BARK_KEY and prints that URL during dry-run execution."}],"files_scanned":2,"total_lines":202,"audit_model":"codex","audited_at":"2026-06-28T20:16:07.889+00:00","created_at":"2026-06-28T21:01:32.688973+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}