{"data":{"skill":{"slug":"cloudai-x-analyzing-projects","name":"analyzing-projects","icon":"📦","repo":"https://github.com/CloudAI-X/claude-workflow/tree/main/skills/analyzing-projects","status":"approved","author":"CloudAI-X","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"5568d158-394b-4413-bce3-44a51a9e32d6","skill_id":"f06c023e-e7f3-4517-8c26-5f52bb57dc68","version":6,"content_hash":"bdcf798e3d2334030236a897730c14ee","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The static command findings are mostly false positives caused by Markdown code fences and inline backticks, not Ruby backtick execution. The skill does instruct assistants to inspect files and may lead users to run package-manager commands in unfamiliar repositories, which creates a real but contextual execution risk. No evidence found of malicious intent, network exfiltration, credential harvesting, obfuscation, or prompt injection.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":28,"line_start":24},{"file":"SKILL.md","line_end":126,"line_start":123},{"file":"SKILL.md","line_end":138,"line_start":138}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":27,"line_start":27}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Project-Provided Commands May Execute Untrusted Code","locations":[{"file":"SKILL.md","line_end":127,"line_start":120},{"file":"SKILL.md","line_end":138,"line_start":138}],"confidence":0.82,"description":"The output template lists package-manager commands such as install, development, test, and build commands. In an unfamiliar project, these commands can execute project-controlled scripts and should require user approval and sandboxing.","confidence_reasoning":"The referenced lines explicitly include npm commands and say development commands should be verified working. This is a legitimate analysis workflow, but it can execute untrusted repository code."},{"title":"Shell-Based Repository Inspection","locations":[{"file":"SKILL.md","line_end":28,"line_start":24}],"confidence":0.74,"description":"The workflow includes shell commands to list files and read README content. These commands are common and low impact, but they still require filesystem access to the target repository.","confidence_reasoning":"The commands are directly present and limited to local inspection. The risk is moderate only when used against untrusted workspaces or sensitive directories."}],"low_findings":[{"title":"Markdown Backticks Misidentified As Ruby Execution","locations":[{"file":"SKILL.md","line_end":20,"line_start":12},{"file":"SKILL.md","line_end":50,"line_start":32},{"file":"SKILL.md","line_end":127,"line_start":89}],"confidence":0.93,"description":"The static analyzer reported many Ruby or shell backtick execution findings. Review shows these are Markdown code fences and inline code examples used to document project markers, not executable Ruby code.","confidence_reasoning":"The matched content is Markdown documentation, not a Ruby source file or executable script. The skill contains no evidence of Ruby backtick command execution."},{"title":"Weak Cryptography Matches Are Textual False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":104,"line_start":93}],"confidence":0.91,"description":"The high-severity weak cryptography matches occur in ordinary prose or template placeholders about architecture and descriptions. No evidence found of cryptographic code, hashing, encryption, or weak algorithm usage.","confidence_reasoning":"The cited lines are descriptive Markdown text and an output template. They do not contain crypto APIs or algorithm selection."},{"title":"README File Access Is Expected For Analysis","locations":[{"file":"SKILL.md","line_end":27,"line_start":27}],"confidence":0.88,"description":"The filesystem finding points to reading README.md during project discovery. This is expected behavior for a codebase analysis skill, but users should avoid running it in directories with unrelated sensitive files.","confidence_reasoning":"The command only reads the local README file and truncates output. It is a real filesystem action, but it is not suspicious by itself."}],"dangerous_patterns":[{"title":"Package Manager Command Execution","locations":[{"file":"SKILL.md","line_end":126,"line_start":123}],"confidence":0.84,"description":"Package-manager commands in the suggested report can run lifecycle scripts or arbitrary repository scripts. Assistants should ask before executing them and prefer static inspection first.","confidence_reasoning":"The commands are visible in the skill template and package managers commonly execute repository-controlled scripts. The skill does not require malicious execution, so this remains a contextual risk."}],"files_scanned":1,"total_lines":143,"audit_model":"codex","audited_at":"2026-06-28T23:09:15.785+00:00","created_at":"2026-06-29T00:44:05.482097+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}