{"data":{"skill":{"slug":"claudate-context-save","name":"context-save","icon":"📦","repo":"https://github.com/Claudate/claude-code-context-sync/tree/main/skills/context-save","status":"approved","author":"Claudate","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"77641a5f-9c87-470f-a050-dce01d8cb111","skill_id":"d0e4e7a8-7503-4e3c-aa3c-ba3463c26c81","version":8,"content_hash":"v3:02f077c174c5335e2f5d02ca15e77b70d9543e58:ffd695f501301808c0ead62202ae38d6142d405e58feca7fd6097c6a2744ebe1:237d1a82ea71e09ba6fb3feb5985a38d97da95bd2de8c2dea404800a76949a0f:736b696c6c732f636c6175646174652f636f6e746578742d73617665:65ea91f0d1a73f91d5967491ff461542","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static external-command, system-reconnaissance, and obfuscation alerts are false positives from Markdown formatting, examples, and readable Chinese prose. No executable shell, Ruby, network, or reconnaissance behavior was found in SKILL.md. A medium-risk issue remains because session notes may persist sensitive context without redaction guidance.","remediation":[{"issue":"Session notes may include secrets or private data.","severity":"medium","suggestion":"Add a required redaction step for tokens, credentials, cookies, private URLs, customer data, and personal data before saving."},{"issue":"Saved context files may be committed with project documentation.","severity":"low","suggestion":"Advise users to review notes before commit, or store sensitive handoff notes in a gitignored location."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":57,"line_start":37},{"file":"SKILL.md","line_end":58,"line_start":57},{"file":"SKILL.md","line_end":65,"line_start":58},{"file":"SKILL.md","line_end":71,"line_start":65},{"file":"SKILL.md","line_end":79,"line_start":71},{"file":"SKILL.md","line_end":95,"line_start":79},{"file":"SKILL.md","line_end":117,"line_start":95},{"file":"SKILL.md","line_end":118,"line_start":117},{"file":"SKILL.md","line_end":119,"line_start":118},{"file":"SKILL.md","line_end":130,"line_start":119}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Unredacted Session Context Persistence","locations":[{"file":"SKILL.md","line_end":25,"line_start":18},{"file":"SKILL.md","line_end":33,"line_start":33}],"confidence":0.86,"description":"The skill instructs the agent to review current session details and save a structured handoff file. It does not require redacting secrets, credentials, cookies, private URLs, or user data before writing the note.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Lines 18-25 define broad context extraction, and line 33 places the result in project documentation. The risk is local persistence of sensitive context, not active exfiltration."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":140,"audit_model":"codex","audited_at":"2026-07-05T06:50:39.701+00:00","created_at":"2026-07-16T17:11:38.377627+00:00","static_findings":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"当用户发送 `换窗口处理-` 时,调用此 Skill。","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**文件命名规则**: `{YYYYMMDD}-{HHMM}-{简短描述}.md`","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"示例: `20251128-1430-实现用户登录功能.md`","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**文件位置**: `docs/context-sessions/`","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":57,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `{文件路径}` - {说明}","category":"external_commands","line_end":58,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `{文件路径}` - {说明}","category":"external_commands","line_end":65,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":79,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":95,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":117,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `electron/services/publish/publishers/wechat.publisher.ts` - 主要开发文件","category":"external_commands","line_end":118,"severity":"medium","line_start":117},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `electron/services/core/cookie.service.ts` - Cookie 管理","category":"external_commands","line_end":119,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `shared/types/publish.types.ts` - 类型定义","category":"external_commands","line_end":130,"severity":"medium","line_start":119},{"id":"blocker:SKILL.md:123:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- 图片需要先上传到微信素材库获取 media_id","category":"blocker","line_end":124,"severity":"low","line_start":123},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-6-74-bits-possible-b","file":"SKILL.md","pattern":"[HEURISTIC] High file entropy (6.74 bits) - possible binary/encrypted content","snippet":"File: SKILL.md","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"Line 10 uses Markdown inline code for the trigger phrase, not Ruby or shell execution. SKILL.md contains prose instructions only and no executable command invocation.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"Line 29 shows a Markdown filename pattern in backticks. This is documentation text for naming a handoff file, not command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Line 31 is an example Markdown filename. It is not shell syntax and does not execute user-controlled input.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"Line 33 wraps a directory path in Markdown backticks. It documents where to save notes and does not invoke an external command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Line 37 opens a fenced Markdown template block. The following content is a note template, not executable Ruby or shell code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Line 57 shows a placeholder file path inside a Markdown template. It is display formatting only and does not run a command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Line 58 repeats a placeholder file path inside the same Markdown template. There is no command interpreter or execution path.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"Line 65 closes a fenced Markdown block. It has no executable behavior.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"Line 71 opens a plain output example block. It documents expected user-facing text and does not execute commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"Line 79 closes the output example block. The backticks are Markdown formatting, not shell execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"Line 95 opens a fenced Markdown example. The content is a sample session note, not executable code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:117:ruby-shell-backtick-execution","reason":"Line 117 contains an example source file path in Markdown backticks. It is a reference inside sample output, not a command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"Line 118 contains another example file path in Markdown backticks. It is documentation text and has no execution mechanism.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"Line 119 contains an example type definition path in Markdown backticks. It is inert Markdown formatting.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:123:system-reconnaissance","reason":"Lines 123-124 discuss a WeChat media_id and login expiration in a sample project note. This is domain-specific documentation, not system reconnaissance.","verdict":"false_positive","confidence":0.94},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-6-74-bits-possible-b","reason":"Manual review shows SKILL.md is readable Markdown with Chinese text, emoji, and fenced examples. There is no binary, encrypted, or obfuscated payload.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[{"title":"Unredacted Session Context Persistence","severity":"medium","locations":[{"file":"SKILL.md","line_end":25,"line_start":18},{"file":"SKILL.md","line_end":33,"line_start":33}],"confidence":0.86,"description":"The skill instructs the agent to review current session details and save a structured handoff file. It does not require redacting secrets, credentials, cookies, private URLs, or user data before writing the note.","confidence_reasoning":"Lines 18-25 define broad context extraction, and line 33 places the result in project documentation. The risk is local persistence of sensitive context, not active exfiltration."}],"subject_marketplace_commit_sha":"02f077c174c5335e2f5d02ca15e77b70d9543e58","subject_content_hash":"ffd695f501301808c0ead62202ae38d6142d405e58feca7fd6097c6a2744ebe1","subject_tree_hash":"237d1a82ea71e09ba6fb3feb5985a38d97da95bd2de8c2dea404800a76949a0f","subject_plugin_path":"skills/claudate/context-save","audit_payload_hash":"65ea91f0d1a73f91d5967491ff461542","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"02f077c174c5335e2f5d02ca15e77b70d9543e58","contentHash":"ffd695f501301808c0ead62202ae38d6142d405e58feca7fd6097c6a2744ebe1","treeHash":"237d1a82ea71e09ba6fb3feb5985a38d97da95bd2de8c2dea404800a76949a0f","pluginPath":"skills/claudate/context-save","auditPayloadHash":"65ea91f0d1a73f91d5967491ff461542"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}