{"data":{"skill":{"slug":"danielmax937-current-location-weather","name":"current-location-weather","icon":"📦","repo":"https://github.com/DanielMax937/pocker/tree/main/current-location-weather/","status":"approved","author":"DanielMax937","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"1a0a5a1b-1da3-41c6-b23a-65c145b2e990","skill_id":"3924c225-7141-445b-bfec-b8ab407059e1","version":6,"content_hash":"20fc64126b361697c12df8b065972349","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"This skill makes legitimate network requests to public weather APIs (ip-api.com and wttr.in) for geolocation and weather data. All static findings for weak cryptography and command execution are false positives caused by documentation examples in markdown backticks and JSON field names. The Python script uses only standard library functions with proper error handling and no user input injection risks.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"scripts/get_weather.py","line_end":24,"line_start":24},{"file":"scripts/get_weather.py","line_end":62,"line_start":62},{"file":"scripts/get_weather.py","line_end":65,"line_start":65},{"file":"scripts/get_weather.py","line_end":69,"line_start":68}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"HTTP endpoint for geolocation","locations":[{"file":"scripts/get_weather.py","line_end":24,"line_start":24}],"description":"The IP geolocation service uses HTTP instead of HTTPS (line 24). While this is a read-only public API with no sensitive data transmission, HTTPS would be preferred. The weather API correctly uses HTTPS."}],"dangerous_patterns":[],"files_scanned":3,"total_lines":651,"audit_model":"claude","audited_at":"2026-01-21T17:28:33.978+00:00","created_at":"2026-01-21T22:37:52.006425+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}