{"data":{"skill":{"slug":"gbsoss-skill-from-masters","name":"skill-from-masters","icon":"📦","repo":"https://github.com/GBSOSS/skill-from-masters/tree/main/skill-from-masters/","status":"approved","author":"GBSOSS","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"ca96fd21-39c8-4f19-8f62-178244dfc320","skill_id":"21267537-b99e-4f1c-99b1-9036cb056095","version":6,"content_hash":"6c7a08aeae8ebf7b142220ec87407961","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static weak cryptography, system reconnaissance, and external command alerts were reviewed as false positives caused by prose, Markdown formatting, and framework names. The only confirmed concern is legitimate web research behavior, which may send user-provided topics to search or browsing tools.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":52,"line_start":40},{"file":"SKILL.md","line_end":64,"line_start":61},{"file":"SKILL.md","line_end":98,"line_start":80}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Static Weak Cryptography Alerts Are False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"references/methodology-database.md","line_end":21,"line_start":21},{"file":"references/methodology-database.md","line_end":32,"line_start":32},{"file":"references/methodology-database.md","line_end":50,"line_start":50},{"file":"references/methodology-database.md","line_end":54,"line_start":53},{"file":"references/methodology-database.md","line_end":56,"line_start":56},{"file":"references/methodology-database.md","line_end":129,"line_start":129},{"file":"references/methodology-database.md","line_end":131,"line_start":131},{"file":"references/methodology-database.md","line_end":135,"line_start":134},{"file":"references/methodology-database.md","line_end":173,"line_start":173},{"file":"references/methodology-database.md","line_end":178,"line_start":178},{"file":"references/methodology-database.md","line_end":214,"line_start":214}],"confidence":0.97,"description":"The flagged locations contain methodology names, expert names, book titles, and prose. I found no cryptographic APIs, hash functions, encryption routines, or credential handling at these locations.","confidence_reasoning":"The surrounding context is plain Markdown reference material. There is no executable code or cryptographic operation to misuse."},{"title":"Static System Reconnaissance Alerts Are Benign Research Text","locations":[{"file":"SKILL.md","line_end":127,"line_start":123},{"file":"SKILL.md","line_end":145,"line_start":145},{"file":"references/methodology-database.md","line_end":12,"line_start":12},{"file":"references/methodology-database.md","line_end":20,"line_start":20},{"file":"references/methodology-database.md","line_end":160,"line_start":160},{"file":"references/methodology-database.md","line_end":172,"line_start":172}],"confidence":0.94,"description":"The flagged lines describe questions, web research checks, and framework references. They do not enumerate local systems, inspect host configuration, or execute discovery commands.","confidence_reasoning":"The suspicious tokens appear in skill workflow prose and a methodology table. I found no command examples such as host, user, process, or network enumeration."},{"title":"Markdown Backticks Mistaken For Command Execution","locations":[{"file":"SKILL.md","line_end":38,"line_start":38}],"confidence":0.99,"description":"The flagged external command location is a Markdown-formatted file path reference. It tells the assistant to read a local reference document and does not invoke Ruby, shell, or subprocess execution.","confidence_reasoning":"The line contains only inline Markdown code formatting around references/methodology-database.md. There is no executable syntax or user-controlled command string."},{"title":"Skill Uses External Web Research","locations":[{"file":"SKILL.md","line_end":52,"line_start":40},{"file":"SKILL.md","line_end":64,"line_start":61},{"file":"SKILL.md","line_end":98,"line_start":80}],"confidence":0.88,"description":"The workflow instructs the assistant to search the web and fetch primary sources. This is legitimate for the skill purpose, but users should avoid including confidential topics in research queries.","confidence_reasoning":"The skill explicitly asks for web searches and source fetching. The behavior is intentional and bounded to research rather than data exfiltration."}],"dangerous_patterns":[],"files_scanned":2,"total_lines":401,"audit_model":"codex","audited_at":"2026-06-30T01:27:30.978+00:00","created_at":"2026-06-30T01:34:41.555448+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}