{"data":{"skill":{"slug":"dietrichgebert-ponytail-help","name":"ponytail-help","icon":"📦","repo":"https://github.com/dietrichgebert/ponytail/tree/cd765194f5e625d2f96e80e63df1c1af0b03705b/skills/ponytail-help","status":"approved","author":"dietrichgebert","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"8b15e27b-3fc6-4d84-bcff-0a201321e8a0","skill_id":"f03a8195-3104-49f6-9a14-3244ab96adab","version":1,"content_hash":"v3:823e459a291299e7796aba8cff0a961cb21ea0c4:dd07abd59ef4acdfc308c193e22b8c526fd99dc1c9a48d710f5ecd5c58b8580c:f84e086756c91334bd695854088fb665e8059ab84c33ade1d3513b694bb96f11:736b696c6c732f64696574726963686765626572742f706f6e797461696c2d68656c70:fac59ad60edc57052f2d829ed11cfd10","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 27 static findings are false positives from Markdown formatting, a documented configuration path, and a reference link. The skill explicitly prohibits mode changes, flag writes, and persistence during help display. No evidence found of prompt injection, credential access, exfiltration, or unauthorized execution in the reviewed file.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":51,"line_start":49},{"file":"SKILL.md","line_end":53,"line_start":51},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":56,"line_start":54},{"file":"SKILL.md","line_end":58,"line_start":56},{"file":"SKILL.md","line_end":59,"line_start":58},{"file":"SKILL.md","line_end":61,"line_start":59},{"file":"SKILL.md","line_end":65,"line_start":61},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":67}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":71,"line_start":71}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":53,"line_start":53}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":72,"audit_model":"codex","audited_at":"2026-10-05T16:42:48.148+00:00","created_at":"2026-10-05T17:06:13.810873+00:00","static_findings":[{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Lite** | `/ponytail lite` | Build what's asked, name the lazier alternative in one line. |","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Full** | `/ponytail` | The ladder enforced: YAGNI → stdlib → native → one line → minimum. Defaul","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Ultra** | `/ponytail ultra` | YAGNI extremist. Deletion before addition. Challenges requirements","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **ponytail** | `/ponytail` | Lazy mode itself. Simplest solution that works. |","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **ponytail-review** | `/ponytail-review` | Over-engineering review: `L42: yagni: factory, one prod","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **ponytail-audit** | `/ponytail-audit` | Whole-repo over-engineering audit: ranked list of what to","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **ponytail-debt** | `/ponytail-debt` | Harvest `ponytail:` shortcut comments into a tracked ledger","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **ponytail-gain** | `/ponytail-gain` | Measured-impact scoreboard: less code, less cost, more spee","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **ponytail-help** | `/ponytail-help` | This card. |","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"In Codex CLI and the IDE extension, invoke skills with `$ponytail:ponytail`,","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`$ponytail:ponytail-review`, or `$ponytail:ponytail-help`. Claude Code and OpenCode use the","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Say \"stop ponytail\" or \"normal mode\". Resume anytime with `/ponytail`.","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`/ponytail off` also works.","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Default mode = `full`, auto-active every session. Change it:","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":51,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Config file** (`~/.config/ponytail/config.json`, Windows: `%APPDATA%\\ponytail\\config.json`):","category":"external_commands","line_end":53,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":56,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":58,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Set `\"off\"` to disable auto-activation on session start, activate manually","category":"external_commands","line_end":59,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"with `/ponytail` when wanted.","category":"external_commands","line_end":61,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Resolution: env var > config file > `full`.","category":"external_commands","line_end":65,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Enable auto-update once: open `/plugin`, go to Marketplaces, pick ponytail, Enable auto-update. Clau","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If `/plugin` is not recognized, your Claude Code is out of date. Update it (`npm install -g @anthrop","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"network:SKILL.md:71:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Full docs + examples: https://github.com/DietrichGebert/ponytail","category":"network","line_end":71,"severity":"low","line_start":71},{"id":"filesystem:SKILL.md:53:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"**Config file** (`~/.config/ponytail/config.json`, Windows: `%APPDATA%\\ponytail\\config.json`):","category":"filesystem","line_end":53,"severity":"high","line_start":53},{"id":"filesystem:SKILL.md:53:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"**Config file** (`~/.config/ponytail/config.json`, Windows: `%APPDATA%\\ponytail\\config.json`):","category":"filesystem","line_end":53,"severity":"medium","line_start":53}],"finding_verdicts":[{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"Backticks format the Lite slash command in a Markdown table. The display-only instruction rules out execution when showing help.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"Backticks mark the Full mode trigger as inline documentation. No shell substitution or Ruby execution appears here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The Ultra slash command is a Markdown table entry, not executable syntax. Help display explicitly must not change mode.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The main Ponytail trigger is documented with inline backticks. The skill displays this reference rather than invoking the listed skill.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"Backticks format a review trigger and an illustrative review comment. Neither is shell execution or an instruction to run code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"This table documents the audit skill trigger. It does not execute an audit or delete repository content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Inline backticks identify a debt skill trigger and its comment marker. The entry describes another skill without executing it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The gain skill trigger is formatted as Markdown inline code. This reference card does not run measurements or external commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"Backticks display the help trigger itself. The surrounding instructions require a one-time reference display without persistence.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The dollar-prefixed text is a documented Codex skill invocation, enclosed in Markdown backticks. It is not shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"These backticks format Codex review and help invocation examples. The prose explains host syntax without requesting execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The inline command illustrates how users resume Ponytail after deactivation. Help display does not perform this mode change.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The off command is a documented deactivation option. Markdown backticks do not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Backticks highlight the default mode name, full. This is a configuration value, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The backticks open a fenced Bash example assigning a non-secret mode environment variable. The display-only skill does not run the example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"These backticks close the Bash documentation fence before the configuration-path explanation. They are Markdown delimiters, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"Backticks format standard application configuration paths on Unix and Windows. No command execution or file operation is requested.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The backticks open a fenced JSON example containing a defaultMode setting. JSON documentation is not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"This is the closing delimiter of a JSON documentation block. The following off value is configuration guidance, not executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"Inline backticks mark the off setting and a manual activation trigger. The card explains choices without changing session state.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The backticks format a manual activation command in explanatory prose. No shell substitution or automatic invocation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The range documents configuration precedence and plugin update commands. Its backticks are Markdown formatting, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The card lists normal plugin management commands for user-controlled updates. It does not run them or fetch and execute untrusted content.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"Inline backticks show standard npm and Homebrew upgrade alternatives for Claude Code. The help-only instruction provides documentation, not automatic installation.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:71:hardcoded-url","reason":"The GitHub URL points to the project documentation. No request, payload transmission, or instruction to send user data appears.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:53:hidden-file-in-home-directory","reason":"The hidden directory is the normal application configuration location, shown only as documentation. The skill explicitly prohibits writes or persistence.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:53:hidden-file-access","reason":"This line names a configuration file without opening, reading, or modifying it. No credential file access or hidden persistence is instructed.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"823e459a291299e7796aba8cff0a961cb21ea0c4","subject_content_hash":"dd07abd59ef4acdfc308c193e22b8c526fd99dc1c9a48d710f5ecd5c58b8580c","subject_tree_hash":"f84e086756c91334bd695854088fb665e8059ab84c33ade1d3513b694bb96f11","subject_plugin_path":"skills/dietrichgebert/ponytail-help","audit_payload_hash":"fac59ad60edc57052f2d829ed11cfd10","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"823e459a291299e7796aba8cff0a961cb21ea0c4","contentHash":"dd07abd59ef4acdfc308c193e22b8c526fd99dc1c9a48d710f5ecd5c58b8580c","treeHash":"f84e086756c91334bd695854088fb665e8059ab84c33ade1d3513b694bb96f11","pluginPath":"skills/dietrichgebert/ponytail-help","auditPayloadHash":"fac59ad60edc57052f2d829ed11cfd10"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/dietrichgebert-ponytail-help/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}