{"data":{"skill":{"slug":"emilkowalski-animation-vocabulary","name":"animation-vocabulary","icon":"📦","repo":"https://github.com/emilkowalski/skills/tree/main/skills/animation-vocabulary/","status":"approved","author":"emilkowalski","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"4617ca31-1ad2-4e2d-9548-c74d75149b5c","skill_id":"3f2b9b1c-4d6d-48f5-beb5-05aebfa894e5","version":2,"content_hash":"v2:b9e5ae9c7a884b8b0bc6894c293164039a0aa79d:d718b48fe3c7898804d588f050a2e266d82c9f5ef51da256c8cb8b5951527757:fb47152988835897e79d77ae2e2d643ee672c974a812cb8c360e565121b92c52:04f6eedb19a31a68dc9d6954d09ad33f","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All ten static findings are false positives. The eight command findings are Markdown code fences, while the two reconnaissance findings are ordinary animation glossary entries with no system inspection behavior.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":14},{"file":"SKILL.md","line_end":34,"line_start":16},{"file":"SKILL.md","line_end":36,"line_start":34},{"file":"SKILL.md","line_end":41,"line_start":36},{"file":"SKILL.md","line_end":47,"line_start":41},{"file":"SKILL.md","line_end":52,"line_start":47},{"file":"SKILL.md","line_end":54,"line_start":52},{"file":"SKILL.md","line_end":58,"line_start":54}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":174,"audit_model":"codex","audited_at":"2026-07-10T16:06:01.472+00:00","created_at":"2026-07-11T00:02:43.058478+00:00","static_findings":[{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":16,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":34,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":36,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":41,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":47,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":52,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":54,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":58,"severity":"medium","line_start":54},{"id":"blocker:SKILL.md:120:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Linear** — Constant speed. Avoid for UI; reserve for spinners or marquees.","category":"blocker","line_end":120,"severity":"low","line_start":120},{"id":"blocker:SKILL.md:148:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Before / after slider** — A draggable divider that wipes between two overlaid images to compare ","category":"blocker","line_end":148,"severity":"low","line_start":148}],"finding_verdicts":[{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"Line 14 opens a Markdown code fence for a formatted response example. It contains no shell command, Ruby expression, or execution instruction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"Line 16 closes the Markdown code fence that begins on line 14. The enclosed text is an animation definition, not executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"Line 34 opens a Markdown code fence for the origin-aware animation output example. No command interpreter or executable syntax is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Line 36 closes a Markdown example block containing plain explanatory text. It does not execute Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"Line 41 opens a Markdown block used to show a disambiguation response. The block contains glossary prose and no external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"Line 47 closes the Markdown response example opened on line 41. The content only compares animation terms.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Line 52 opens a Markdown code fence for a rubber-banding definition. There is no shell or Ruby execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Line 54 closes a plain-text Markdown example. It contains no executable command, arguments, or user-controlled input.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:120:system-reconnaissance","reason":"Line 120 defines linear animation as constant-speed motion and mentions interface use cases. It does not inspect the host system or collect environment details.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:148:system-reconnaissance","reason":"Line 148 defines a visual before-and-after slider. It describes image comparison behavior and performs no system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}