{"data":{"skill":{"slug":"cloudai-x-designing-tests","name":"designing-tests","icon":"📦","repo":"https://github.com/CloudAI-X/claude-workflow/tree/main/skills/designing-tests","status":"approved","author":"CloudAI-X","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"e815820a-b73f-4c5b-b63a-c217636ff3cf","skill_id":"562f939f-65a6-49c2-aa6b-83785b3dd48c","version":6,"content_hash":"5eae96d65c74b545fe31ad5817e22bdd","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged many backticks, weak cryptography keywords, reconnaissance terms, and HTTP patterns. Manual review found Markdown test examples, local test commands, and mock HTTP handlers, with no malicious intent or prompt injection evidence.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":216,"line_start":215},{"file":"SKILL.md","line_end":235,"line_start":224}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":102,"line_start":100},{"file":"SKILL.md","line_end":201,"line_start":193}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Markdown Backtick Findings Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":37,"line_start":12},{"file":"SKILL.md","line_end":236,"line_start":67}],"confidence":0.94,"description":"The external command detections point to Markdown fences, JavaScript examples, JSON examples, and inline test commands. The skill does not execute these snippets by itself.","confidence_reasoning":"The matched backticks are visible Markdown code fences and inline examples. No executable wrapper, script file, or hidden automation is present."},{"title":"Test Command Guidance Requires Normal Local Execution","verdict":"TRUE_POSITIVE_LOW_RISK","locations":[{"file":"SKILL.md","line_end":216,"line_start":215},{"file":"SKILL.md","line_end":235,"line_start":224}],"confidence":0.82,"description":"The skill recommends commands such as npm test and coverage runs. This is expected for a testing skill, but users should run commands only in trusted repositories.","confidence_reasoning":"The commands are explicit and limited to test execution. They can run project-defined scripts, so the operational risk is real but normal for test automation."},{"title":"HTTP Patterns Are Local Testing Examples","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":102,"line_start":100},{"file":"SKILL.md","line_end":201,"line_start":193}],"confidence":0.9,"description":"The network detections are SuperTest style request usage and an MSW mock handler. They demonstrate local API testing and do not contact an external service.","confidence_reasoning":"The HTTP examples use relative paths and mocking libraries. There is no external URL, credential handling, or data exfiltration pattern."},{"title":"Weak Cryptography Detections Are Keyword Matches","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":6,"line_start":2},{"file":"SKILL.md","line_end":69,"line_start":68},{"file":"SKILL.md","line_end":112,"line_start":90},{"file":"SKILL.md","line_end":165,"line_start":160},{"file":"SKILL.md","line_end":219,"line_start":219}],"confidence":0.96,"description":"The flagged lines contain the skill name, describe blocks, test names, and object spread syntax. No cryptographic algorithm usage was found.","confidence_reasoning":"Manual review found no MD5, DES, SHA1, cipher, hash, or crypto API calls. The matches appear to be substrings inside documentation and sample tests."},{"title":"System Reconnaissance Detections Are Documentation Text","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":81,"line_start":81}],"confidence":0.93,"description":"The flagged reconnaissance lines are testing pyramid guidance and sample test text. No command gathers host, network, process, or environment information.","confidence_reasoning":"The content is instructional testing material. No system inspection commands or data collection logic are present."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":237,"audit_model":"codex","audited_at":"2026-06-28T23:18:37.853+00:00","created_at":"2026-06-29T00:44:06.021828+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":4,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}