{"data":{"skill":{"slug":"equinor-fusion-issue-authoring","name":"fusion-issue-authoring","icon":"📦","repo":"https://github.com/equinor/fusion-skills/tree/8ae37cccd02414337f0efbad174f20ce50027523/skills/fusion-issue-authoring","status":"approved","author":"equinor","authorVersion":"0.3.5","skillstoreRevision":1},"audit":{"id":"1e2b3381-0024-4d90-adca-e3233da9cb4a","skill_id":"ebbe334f-101c-4d1b-83d1-b1fab617e703","version":1,"content_hash":"v3:7562931ce7d490305c630ba8341f38a5e060bcd8:d01f90f03633a2cbcf8ed6921a51d6116aa88b1360ff4f312b2fd2ea03a4fe98:ad8f522cf3ca7d258007b0d470a1eb2a0ae1de2eb87fa3ced3b791bc0fa8c7ff:736b696c6c732f657175696e6f722f667573696f6e2d69737375652d617574686f72696e67:7290ceedeeab89edc1ed36f27aeba7f6","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 79 static alerts are false positives caused by Markdown formatting, GraphQL fields, release notes, and GitHub documentation. The skill gates GitHub mutations behind explicit approval and shows no prompt injection, credential access, or malicious intent.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"assets/graphql/README.md","line_end":30,"line_start":30},{"file":"references/mcp-server.md","line_end":42,"line_start":42}]},{"factor":"external_commands","evidence":[{"file":"CHANGELOG.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":93,"line_start":93},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":112,"line_start":112},{"file":"SKILL.md","line_end":118,"line_start":118},{"file":"SKILL.md","line_end":119,"line_start":119},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":125,"line_start":125},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":134,"line_start":134},{"file":"SKILL.md","line_end":136,"line_start":136},{"file":"SKILL.md","line_end":137,"line_start":137},{"file":"SKILL.md","line_end":139,"line_start":139},{"file":"SKILL.md","line_end":140,"line_start":140},{"file":"SKILL.md","line_end":149,"line_start":149},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":161,"line_start":161},{"file":"SKILL.md","line_end":162,"line_start":162},{"file":"SKILL.md","line_end":163,"line_start":163},{"file":"SKILL.md","line_end":164,"line_start":164},{"file":"SKILL.md","line_end":168,"line_start":168},{"file":"SKILL.md","line_end":174,"line_start":174},{"file":"SKILL.md","line_end":183,"line_start":183},{"file":"SKILL.md","line_end":192,"line_start":192},{"file":"SKILL.md","line_end":193,"line_start":193}]},{"factor":"env_access","evidence":[{"file":"references/mcp-server.md","line_end":197,"line_start":197}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":29,"total_lines":1505,"audit_model":"codex","audited_at":"2026-08-26T08:36:29.747+00:00","created_at":"2026-08-26T09:54:20.584227+00:00","static_findings":[{"id":"blocker:agents/devils-advocate.agent.md:15:system-reconnaissance","file":"agents/devils-advocate.agent.md","pattern":"System reconnaissance","snippet":"- The user has explicitly said they don't want pushback on this iteration","category":"blocker","line_end":15,"severity":"low","line_start":15},{"id":"blocker:assets/graphql/issue_lookup.github.graphql:4:system-reconnaissance","file":"assets/graphql/issue_lookup.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":5,"severity":"low","line_start":4},{"id":"blocker:assets/graphql/issue_lookup.github.graphql:9:system-reconnaissance","file":"assets/graphql/issue_lookup.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":10,"severity":"low","line_start":9},{"id":"blocker:assets/graphql/issue_lookup.github.graphql:13:system-reconnaissance","file":"assets/graphql/issue_lookup.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":14,"severity":"low","line_start":13},{"id":"blocker:assets/graphql/issue_type_update.github.graphql:4:system-reconnaissance","file":"assets/graphql/issue_type_update.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":5,"severity":"low","line_start":4},{"id":"blocker:assets/graphql/issue_type_update.github.graphql:7:system-reconnaissance","file":"assets/graphql/issue_type_update.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":8,"severity":"low","line_start":7},{"id":"blocker:assets/graphql/issue_types_list.github.graphql:5:system-reconnaissance","file":"assets/graphql/issue_types_list.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":6,"severity":"low","line_start":5},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:4:system-reconnaissance","file":"assets/graphql/linkage_verify.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":5,"severity":"low","line_start":4},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:9:system-reconnaissance","file":"assets/graphql/linkage_verify.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":10,"severity":"low","line_start":9},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:13:system-reconnaissance","file":"assets/graphql/linkage_verify.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":14,"severity":"low","line_start":13},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:17:system-reconnaissance","file":"assets/graphql/linkage_verify.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":18,"severity":"low","line_start":17},{"id":"network:assets/graphql/README.md:30:python-http-libraries","file":"assets/graphql/README.md","pattern":"Python HTTP libraries","snippet":"- **Secondary limits**: mutations cost 5 points, read queries cost 1 point. Max 2,000 points/minute.","category":"network","line_end":30,"severity":"low","line_start":30},{"id":"blocker:assets/graphql/README.md:41:system-reconnaissance","file":"assets/graphql/README.md","pattern":"System reconnaissance","snippet":"- Keep `first`/`last` arguments small to reduce point cost and avoid timeouts.","category":"blocker","line_end":41,"severity":"low","line_start":41},{"id":"blocker:assets/graphql/sub_issue_remove.github.graphql:4:system-reconnaissance","file":"assets/graphql/sub_issue_remove.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":5,"severity":"low","line_start":4},{"id":"blocker:assets/graphql/sub_issue_remove.github.graphql:7:system-reconnaissance","file":"assets/graphql/sub_issue_remove.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":8,"severity":"low","line_start":7},{"id":"blocker:assets/graphql/sub_issue_reprioritize.github.graphql:6:system-reconnaissance","file":"assets/graphql/sub_issue_reprioritize.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":7,"severity":"low","line_start":6},{"id":"blocker:assets/graphql/sub_issue_write.github.graphql:4:system-reconnaissance","file":"assets/graphql/sub_issue_write.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":5,"severity":"low","line_start":4},{"id":"blocker:assets/graphql/sub_issue_write.github.graphql:7:system-reconnaissance","file":"assets/graphql/sub_issue_write.github.graphql","pattern":"System reconnaissance","snippet":"id","category":"blocker","line_end":8,"severity":"low","line_start":7},{"id":"external_commands:CHANGELOG.md:160:powershell-invocation","file":"CHANGELOG.md","pattern":"PowerShell invocation","snippet":"- switch issue-type updates to GraphQL `updateIssue(issueTypeId: ...)` in shell and PowerShell helpe","category":"external_commands","line_end":160,"severity":"high","line_start":160},{"id":"blocker:CHANGELOG.md:17:system-reconnaissance","file":"CHANGELOG.md","pattern":"System reconnaissance","snippet":"- [#153](https://github.com/equinor/fusion-skills/pull/153) [`3911da5`](https://github.com/equinor/f","category":"blocker","line_end":17,"severity":"low","line_start":17},{"id":"blocker:CHANGELOG.md:22:system-reconnaissance","file":"CHANGELOG.md","pattern":"System reconnaissance","snippet":"- Add a troubleshooting table covering 404, invalid input, and silent-failure modes","category":"blocker","line_end":22,"severity":"low","line_start":22},{"id":"blocker:CHANGELOG.md:110:system-reconnaissance","file":"CHANGELOG.md","pattern":"System reconnaissance","snippet":"- Clarify cache-first behavior for labels and issue types to avoid repeated lookups","category":"blocker","line_end":110,"severity":"low","line_start":110},{"id":"blocker:CHANGELOG.md:162:system-reconnaissance","file":"CHANGELOG.md","pattern":"System reconnaissance","snippet":"- guard `set -u` in VS Code integrated zsh sessions to avoid shell integration hook failures","category":"blocker","line_end":162,"severity":"low","line_start":162},{"id":"blocker:CHANGELOG.md:94:network-reconnaissance","file":"CHANGELOG.md","pattern":"Network reconnaissance","snippet":"- `fusion-issue-solving`: expanded low-token strategy with session-cache references and budget aware","category":"blocker","line_end":95,"severity":"low","line_start":94},{"id":"blocker:references/instructions.md:12:system-reconnaissance","file":"references/instructions.md","pattern":"System reconnaissance","snippet":"- MCP tools first; avoid ad hoc GitHub API/GraphQL retries when MCP equivalent exists","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"blocker:references/instructions.md:47:network-reconnaissance","file":"references/instructions.md","pattern":"Network reconnaissance","snippet":"- Use cached issue types; call `mcp_github::list_issue_types` only on cache miss","category":"blocker","line_end":48,"severity":"low","line_start":47},{"id":"network:references/mcp-server.md:42:hardcoded-url","file":"references/mcp-server.md","pattern":"Hardcoded URL","snippet":"\"url\": \"https://api.githubcopilot.com/mcp/\"","category":"network","line_end":42,"severity":"low","line_start":42},{"id":"env_access:references/mcp-server.md:197:git-platform-tokens","file":"references/mcp-server.md","pattern":"Git platform tokens","snippet":"| Primary budget | 5,000 pts/hour per user (1,000 for `GITHUB_TOKEN` in Actions) |","category":"env_access","line_end":197,"severity":"high","line_start":197},{"id":"blocker:references/mcp-server.md:59:system-reconnaissance","file":"references/mcp-server.md","pattern":"System reconnaissance","snippet":"Optional. Get valid values with `mcp_github::list_issue_types`. Send only when repo has issue types ","category":"blocker","line_end":59,"severity":"low","line_start":59},{"id":"blocker:references/mcp-server.md:98:system-reconnaissance","file":"references/mcp-server.md","pattern":"System reconnaissance","snippet":"- Avoid broad repeated searches after mutation failures; resolve auth/config first.","category":"blocker","line_end":98,"severity":"low","line_start":98},{"id":"blocker:references/mcp-server.md:166:system-reconnaissance","file":"references/mcp-server.md","pattern":"System reconnaissance","snippet":"| \"Invalid input\" error | `sub_issue_id` missing or wrong format | Confirm value is a numeric ID (e.","category":"blocker","line_end":166,"severity":"low","line_start":166},{"id":"blocker:references/mcp-server.md:206:system-reconnaissance","file":"references/mcp-server.md","pattern":"System reconnaissance","snippet":"- Stop optional label/assignee enrichments and avoid automatic retry loops.","category":"blocker","line_end":206,"severity":"low","line_start":206},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `agents/bug.agent.md`: bug-focused issue drafting and triage structure","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `agents/feature.agent.md`: feature-focused scope and acceptance structure","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `agents/user-story.agent.md`: role/workflow/scenario-driven story structure","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `agents/task.agent.md`: checklist-first task decomposition and dependency planning","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `agents/devils-advocate.agent.md`: always-on quality collaborator that raises key concerns after c","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Repository label set (or confirmation labels are intentionally skipped). Cache full label set per ","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Assignee preference (`@me`, specific person, or unassigned). Reuse cached assignee-candidate resul","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If required details are missing, ask concise clarifying questions from `references/questions.md`.","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Classify request as `Bug`, `Feature`, `User Story`, or `Task`, then activate the matching agent mode","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Bug -> `agents/bug.agent.md`","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Feature -> `agents/feature.agent.md`","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- User Story -> `agents/user-story.agent.md`","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Task -> `agents/task.agent.md`","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Devil's advocate pass: `agents/devils-advocate.agent.md` is always active in moderate mode — it surf","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- When no explicit repository is given, check the active workspace for contributor guides (`CONTRIBU","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. repository template (`.github/ISSUE_TEMPLATE/`)","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run one focused duplicate search with `mcp_github::search_issues` and surface matches before draftin","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Before writing, check user preferences and session memory for a preferred draft location. If a store","category":"external_commands","line_end":93,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- assignee intent (`@me`, specific login, or unassigned)","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- On the first label lookup for `owner/repo`, fetch the repository label set once and cache it for t","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If the host only exposes point label lookups and no cached label set exists yet, do not loop throu","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Skip `mcp_github::search_users` when the user already gave `@me` or an exact GitHub login.","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- When assignee lookup is needed, cache candidate results for the active session keyed by owner/repo","category":"external_commands","line_end":112,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `mcp_github::issue_write` create/update with the full known payload (`title`, `body`, and include","category":"external_commands","line_end":118,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Optional single follow-up `mcp_github::issue_write` only when required fields were unknown in ste","category":"external_commands","line_end":119,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `mcp_github::sub_issue_write` only when relationship/order changes are requested","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `mcp_github::add_issue_comment` only when blocker/status notes are explicitly requested","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- guide user to setup steps in `references/mcp-server.md`","category":"external_commands","line_end":125,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Detect and report rate-limit failures clearly (`API rate limit exceeded`, `secondary rate limit`, ","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Prefer MCP tools over ad hoc `gh api`/GraphQL retries when equivalent MCP capability exists.","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Respect `retry-after` and `x-ratelimit-reset` headers before retrying any request.","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`type` rule:","category":"external_commands","line_end":136,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Only use `type` if the repository has issue types configured.","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Call `mcp_github::list_issue_types` only on cache miss or invalid cache.","category":"external_commands","line_end":139,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If issue types are not supported, omit `type` for the rest of the session.","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use detailed behavior and payload examples in `references/instructions.md` and `references/mcp-serve","category":"external_commands","line_end":149,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use detailed authoring guidance in `references/instructions.md`.","category":"external_commands","line_end":159,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Bug: `assets/issue-templates/bug.md`","category":"external_commands","line_end":161,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Feature: `assets/issue-templates/feature.md`","category":"external_commands","line_end":162,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- User Story: `assets/issue-templates/user-story.md`","category":"external_commands","line_end":163,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Task: `assets/issue-templates/task*.md`","category":"external_commands","line_end":164,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Draft issue file path under `.tmp/`","category":"external_commands","line_end":168,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Explicit status: `Awaiting user content approval` before any publish/update command","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Run `mcp_github::issue_write` create/update without explicit user confirmation","category":"external_commands","line_end":183,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use full repository issue references (for example `owner/repo#123`)","category":"external_commands","line_end":192,"severity":"medium","line_start":192},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use issue-closing keywords when closure is intended (for example `fixes owner/repo#123`, `resolves","category":"external_commands","line_end":193,"severity":"medium","line_start":193},{"id":"blocker:SKILL.md:139:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Call `mcp_github::list_issue_types` only on cache miss or invalid cache.","category":"blocker","line_end":139,"severity":"low","line_start":139}],"finding_verdicts":[{"id":"blocker:agents/devils-advocate.agent.md:15:system-reconnaissance","reason":"This line respects a user preference against further challenge. It requests no system information and does not bypass security controls.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/issue_lookup.github.graphql:4:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/issue_lookup.github.graphql:9:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/issue_lookup.github.graphql:13:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/issue_type_update.github.graphql:4:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/issue_type_update.github.graphql:7:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/issue_types_list.github.graphql:5:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:4:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:9:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:13:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/linkage_verify.github.graphql:17:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/graphql/README.md:30:python-http-libraries","reason":"This line documents GitHub GraphQL rate limits. It contains no Python library call, executable request, or data transfer.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/README.md:41:system-reconnaissance","reason":"This is defensive rate-limit guidance about GraphQL pagination size. It neither inventories the host nor gathers sensitive system data.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/sub_issue_remove.github.graphql:4:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/sub_issue_remove.github.graphql:7:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/sub_issue_reprioritize.github.graphql:6:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/sub_issue_write.github.graphql:4:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/graphql/sub_issue_write.github.graphql:7:system-reconnaissance","reason":"The match is a GraphQL id response field used for GitHub issue operations. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:CHANGELOG.md:160:powershell-invocation","reason":"This is release-note prose mentioning PowerShell helpers. It contains no PowerShell invocation or executable command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:17:system-reconnaissance","reason":"This is release-note prose describing prior maintenance. It does not direct host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:22:system-reconnaissance","reason":"This is release-note prose describing prior maintenance. It does not direct host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:110:system-reconnaissance","reason":"This is release-note prose describing prior maintenance. It does not direct host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:162:system-reconnaissance","reason":"This is release-note prose describing prior maintenance. It does not direct host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:CHANGELOG.md:94:network-reconnaissance","reason":"This is release-note prose describing prior maintenance. It does not direct host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/instructions.md:12:system-reconnaissance","reason":"This line limits GitHub lookups and retries through cache-first MCP guidance. It does not perform network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/instructions.md:47:network-reconnaissance","reason":"This line limits GitHub lookups and retries through cache-first MCP guidance. It does not perform network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"network:references/mcp-server.md:42:hardcoded-url","reason":"The URL is the documented GitHub Copilot MCP endpoint in an explicit server configuration example. It is not an exfiltration destination.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/mcp-server.md:197:git-platform-tokens","reason":"The line names GITHUB_TOKEN only while documenting GitHub rate limits. It does not read, print, transmit, or request any token value.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/mcp-server.md:59:system-reconnaissance","reason":"This is defensive GitHub MCP usage and troubleshooting guidance. It limits requests and does not probe the host or unrelated networks.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/mcp-server.md:98:system-reconnaissance","reason":"This is defensive GitHub MCP usage and troubleshooting guidance. It limits requests and does not probe the host or unrelated networks.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/mcp-server.md:166:system-reconnaissance","reason":"This is defensive GitHub MCP usage and troubleshooting guidance. It limits requests and does not probe the host or unrelated networks.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/mcp-server.md:206:system-reconnaissance","reason":"This is defensive GitHub MCP usage and troubleshooting guidance. It limits requests and does not probe the host or unrelated networks.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"The backticks format MCP tool names in a confirmation-gated GitHub workflow. They are not Ruby interpolation or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The backticks format MCP tool names in a confirmation-gated GitHub workflow. They are not Ruby interpolation or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks format MCP tool names in a confirmation-gated GitHub workflow. They are not Ruby interpolation or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The backticks format MCP tool names in a confirmation-gated GitHub workflow. They are not Ruby interpolation or shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The line discourages ad hoc gh and GraphQL retries in favor of MCP. The backticks are Markdown, not an executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The surrounding safety rule explicitly prohibits issue mutation without user confirmation. Markdown backticks do not execute the named MCP tool.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting for paths, values, statuses, or MCP names. No Ruby interpolation or shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:139:system-reconnaissance","reason":"The line allows one GitHub issue-type lookup after a cache miss. It is scoped application metadata access, not system reconnaissance.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":"7562931ce7d490305c630ba8341f38a5e060bcd8","subject_content_hash":"d01f90f03633a2cbcf8ed6921a51d6116aa88b1360ff4f312b2fd2ea03a4fe98","subject_tree_hash":"ad8f522cf3ca7d258007b0d470a1eb2a0ae1de2eb87fa3ced3b791bc0fa8c7ff","subject_plugin_path":"skills/equinor/fusion-issue-authoring","audit_payload_hash":"7290ceedeeab89edc1ed36f27aeba7f6","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"7562931ce7d490305c630ba8341f38a5e060bcd8","contentHash":"d01f90f03633a2cbcf8ed6921a51d6116aa88b1360ff4f312b2fd2ea03a4fe98","treeHash":"ad8f522cf3ca7d258007b0d470a1eb2a0ae1de2eb87fa3ced3b791bc0fa8c7ff","pluginPath":"skills/equinor/fusion-issue-authoring","auditPayloadHash":"7290ceedeeab89edc1ed36f27aeba7f6"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/equinor-fusion-issue-authoring/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}