{"data":{"skill":{"slug":"glenskii-universal-audit","name":"universal-audit","icon":"📦","repo":"https://github.com/glenskii/glenski-plugins/tree/60a0fdb8645aff907f29880bc70b1ee62ec7309c/plugins/glenski-quality-suite/skills/universal-audit","status":"approved","author":"glenskii","authorVersion":"1.0.3","skillstoreRevision":2},"audit":{"id":"59426a8d-a085-45ff-9aba-ca9b3e7904c8","skill_id":"2ba2078b-513b-448c-8917-d8528cce3ca7","version":2,"content_hash":"v3:f4838806900353c20a6899b1cbb5f5bc3a23357a:870bfd2893a4b50a25a368d601ebdc316c234d0a044832a9262e49067a961bf3:3911574ab963f262e2e43e305146f606ae177845e11add3d8e88e7fb89142753:736b696c6c732f676c656e736b69692f756e6976657273616c2d6175646974:27f97523de1df816728cd9016dcc5957","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 56 static findings are false positives caused by Markdown formatting, JSON Schema identifiers, audit terminology, or expected local artifact output. The reviewed procedures require authorization for active testing, default to passive inspection, and prohibit unsafe or unauthorized actions.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/schemas/audit-manifest.schema.json","line_end":2,"line_start":2},{"file":"references/schemas/evidence.schema.json","line_end":2,"line_start":2},{"file":"references/schemas/finding.schema.json","line_end":2,"line_start":2},{"file":"references/schemas/selected-controls.schema.json","line_end":2,"line_start":2}]},{"factor":"filesystem","evidence":[{"file":"scripts/score.py","line_end":352,"line_start":352}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":11,"line_start":11},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":61,"line_start":58},{"file":"SKILL.md","line_end":70,"line_start":61},{"file":"SKILL.md","line_end":74,"line_start":70},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":76,"line_start":76}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":18,"total_lines":2534,"audit_model":"codex","audited_at":"2026-08-09T08:35:02.938+00:00","created_at":"2026-08-09T10:25:35.9453+00:00","static_findings":[{"id":"blocker:references/control-procedures.md:8:system-reconnaissance","file":"references/control-procedures.md","pattern":"System reconnaissance","snippet":"commit/build, and the sanitized result in the evidence ledger. A check you did not run","category":"blocker","line_end":8,"severity":"low","line_start":8},{"id":"blocker:references/control-procedures.md:81:system-reconnaissance","file":"references/control-procedures.md","pattern":"System reconnaissance","snippet":"critical invariants - not just app-layer validation. ⚠ attempt an invalid insert in a","category":"blocker","line_end":81,"severity":"low","line_start":81},{"id":"blocker:references/control-procedures.md:51:network-reconnaissance","file":"references/control-procedures.md","pattern":"Network reconnaissance","snippet":"## ARC / CODE - Architecture and code correctness","category":"blocker","line_end":53,"severity":"low","line_start":51},{"id":"blocker:references/depth-and-profiles.md:16:system-reconnaissance","file":"references/depth-and-profiles.md","pattern":"System reconnaissance","snippet":"- Rapid selects R controls; Standard selects R+S; Deep selects R+S+D.","category":"blocker","line_end":16,"severity":"low","line_start":16},{"id":"blocker:references/depth-and-profiles.md:17:system-reconnaissance","file":"references/depth-and-profiles.md","pattern":"System reconnaissance","snippet":"- Rapid audits can never issue APPROVED unless every approval gate is independently","category":"blocker","line_end":17,"severity":"low","line_start":17},{"id":"blocker:references/depth-and-profiles.md:20:system-reconnaissance","file":"references/depth-and-profiles.md","pattern":"System reconnaissance","snippet":"challenger that did not author the findings.","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"network:references/schemas/audit-manifest.schema.json:2:hardcoded-url","file":"references/schemas/audit-manifest.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:references/schemas/evidence.schema.json:2:hardcoded-url","file":"references/schemas/evidence.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:references/schemas/finding.schema.json:2:hardcoded-url","file":"references/schemas/finding.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"network:references/schemas/selected-controls.schema.json:2:hardcoded-url","file":"references/schemas/selected-controls.schema.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft/2020-12/schema\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"blocker:references/schemas/selected-controls.schema.json:14:system-reconnaissance","file":"references/schemas/selected-controls.schema.json","pattern":"System reconnaissance","snippet":"\"description\": \"Required for rapid audits: count of applicable R+S controls under the same applicabi","category":"blocker","line_end":14,"severity":"low","line_start":14},{"id":"blocker:references/templates/intake-template.md:9:system-reconnaissance","file":"references/templates/intake-template.md","pattern":"System reconnaissance","snippet":"- Depth tier: rapid / standard / deep","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:references/templates/report-template.md:37:system-reconnaissance","file":"references/templates/report-template.md","pattern":"System reconnaissance","snippet":"**Overall evidence coverage:** {{COVERAGE}} <!-- Rapid audits: show both denominators -->","category":"blocker","line_end":37,"severity":"low","line_start":37},{"id":"filesystem:scripts/score.py:352:python-file-write-append","file":"scripts/score.py","pattern":"Python file write/append","snippet":"with open(args.out, \"w\", encoding=\"utf-8\") as f:","category":"filesystem","line_end":352,"severity":"medium","line_start":352},{"id":"blocker:scripts/score.py:129:system-reconnaissance","file":"scripts/score.py","pattern":"System reconnaissance","snippet":"cid = control[\"control_id\"]","category":"blocker","line_end":129,"severity":"low","line_start":129},{"id":"blocker:scripts/score.py:130:system-reconnaissance","file":"scripts/score.py","pattern":"System reconnaissance","snippet":"if cid in GATE_CONTROLS:","category":"blocker","line_end":130,"severity":"low","line_start":130},{"id":"blocker:scripts/score.py:134:system-reconnaissance","file":"scripts/score.py","pattern":"System reconnaissance","snippet":"if cid in EXCEPTION_MAP:","category":"blocker","line_end":134,"severity":"low","line_start":134},{"id":"blocker:scripts/score.py:261:system-reconnaissance","file":"scripts/score.py","pattern":"System reconnaissance","snippet":"sys.exit(f\"ERROR: {c['control_id']}: invalid status '{c['status']}'\")","category":"blocker","line_end":261,"severity":"low","line_start":261},{"id":"blocker:scripts/score.py:320:system-reconnaissance","file":"scripts/score.py","pattern":"System reconnaissance","snippet":"# ---- Rapid audits also report the Standard-tier denominator (spec 13.3) ----","category":"blocker","line_end":320,"severity":"low","line_start":320},{"id":"blocker:scripts/score.py:370:system-reconnaissance","file":"scripts/score.py","pattern":"System reconnaissance","snippet":"cov_line += f\" (rapid denominator), {std_denominator_coverage}% (standard denominator)\"","category":"blocker","line_end":370,"severity":"low","line_start":370},{"id":"external_commands:SKILL.md:11:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"This skill executes the **Universal Software Engineering Audit Specification v2.2** (bundled at `spe","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Confirm the target: repo path, running URL, or both. Read `package.json` / `requirements.txt` / `","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Fill the intake from `references/templates/intake-template.md`. Ask the operator only for items y","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Declare: audit type, depth tier (rapid / standard / deep), environment, access level, assurance o","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Assign the audit ID: `AUD-[PRODUCT]-[YYYYMMDD]-[SEQ]`.","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. Gate controls: evaluate `GOV-SCOPE-001` and `GOV-ROE-001` first. If either cannot PASS, the engag","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. Create the artifact directory: `audits/<audit-id>/` in the project root (or an operator-specified","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Write `selected-controls.json` (schema in `references/schemas/`). This freezes the coverage denom","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Work the spec Section 12 order. For each selected control, gather the minimum PASS evidence listed i","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Record every material observation in `evidence-ledger.json`: ID, class, timestamp, location (file:","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Repository unavailable: source-dependent claims are `UNVERIFIED - Runtime inference only`.","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Every FAIL and WARN becomes a finding using the twenty-field standard (spec Section 9), written t","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Run `scripts/score.py`:","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":61,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":70,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Record each challenge outcome: UPHELD / MODIFIED / REJECTED / NEEDS MORE EVIDENCE, with rationale, i","category":"external_commands","line_end":74,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Render `report.md` from `references/templates/report-template.md`. Executive summary is seven sen","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Final artifact set in `audits/<audit-id>/`: `audit-manifest.json`, `selected-controls.json`, `evi","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"blocker:SKILL.md:24:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"3. Declare: audit type, depth tier (rapid / standard / deep), environment, access level, assurance o","category":"blocker","line_end":24,"severity":"low","line_start":24},{"id":"blocker:SKILL.md:28:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"7. Create the artifact directory: `audits/<audit-id>/` in the project root (or an operator-specified","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:SKILL.md:32:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"1. Load the catalog: spec Appendix A. Select every control at or below the declared tier (Rapid = R;","category":"blocker","line_end":32,"severity":"low","line_start":32},{"id":"blocker:SKILL.md:63:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"It computes per-category provisional scores, applies the mandatory caps, computes tier-relative cove","category":"blocker","line_end":63,"severity":"low","line_start":63},{"id":"blocker:SKILL.md:68:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Standard tier: run a separate contradiction pass - a fresh subagent that did not author the findings","category":"blocker","line_end":68,"severity":"low","line_start":68},{"id":"blocker:SKILL.md:68:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"Standard tier: run a separate contradiction pass - a fresh subagent that did not author the findings","category":"blocker","line_end":68,"severity":"low","line_start":68},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:123:system-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"System reconnaissance","snippet":"| Requirement | Rapid | Standard | Deep |","category":"blocker","line_end":123,"severity":"low","line_start":123},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:512:system-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"System reconnaissance","snippet":"- Invalid and adversarial input","category":"blocker","line_end":512,"severity":"low","line_start":512},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:654:system-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"System reconnaissance","snippet":"Coverage is tier-relative and must be labeled with its tier. Every Rapid audit must additionally rep","category":"blocker","line_end":654,"severity":"low","line_start":654},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:794:system-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"System reconnaissance","snippet":"- New paid services without a justified return","category":"blocker","line_end":794,"severity":"low","line_start":794},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:856:system-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"System reconnaissance","snippet":"Rapid audits should use the same structure when tooling permits.","category":"blocker","line_end":856,"severity":"low","line_start":856},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:981:system-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"System reconnaissance","snippet":"For Standard audits, perform a separate contradiction pass after drafting findings. For Deep audits ","category":"blocker","line_end":981,"severity":"low","line_start":981},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:182:network-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"Network reconnaissance","snippet":"- CI/CD and release process","category":"blocker","line_end":183,"severity":"low","line_start":182},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:203:network-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"Network reconnaissance","snippet":"- Configuration access","category":"blocker","line_end":204,"severity":"low","line_start":203},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:204:network-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"Network reconnaissance","snippet":"- Logs and monitoring access","category":"blocker","line_end":205,"severity":"low","line_start":204},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:246:network-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"Network reconnaissance","snippet":"- Incident escalation process","category":"blocker","line_end":247,"severity":"low","line_start":246},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:288:network-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"Network reconnaissance","snippet":"- Evidence class","category":"blocker","line_end":289,"severity":"low","line_start":288},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:640:network-reconnaissance","file":"spec/Universal_Software_Engineering_Audit_Specification.md","pattern":"Network reconnaissance","snippet":"- **9.0–10.0:** Strong controls, extensively verified, no material unresolved weakness","category":"blocker","line_end":641,"severity":"low","line_start":640}],"finding_verdicts":[{"id":"blocker:references/control-procedures.md:8:system-reconnaissance","reason":"The line defines evidence-recording requirements and marks unperformed checks as unverified. It does not direct system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/control-procedures.md:81:system-reconnaissance","reason":"The line describes an invalid database insert only in a test environment and marks it as requiring authorization. This is a bounded audit control, not unauthorized reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/control-procedures.md:51:network-reconnaissance","reason":"The cited line is a section heading for architecture and code correctness. It contains no network operation or reconnaissance instruction.","verdict":"false_positive","confidence":1},{"id":"blocker:references/depth-and-profiles.md:16:system-reconnaissance","reason":"The line maps audit depth tiers to control sets. It does not inspect or enumerate any system.","verdict":"false_positive","confidence":1},{"id":"blocker:references/depth-and-profiles.md:17:system-reconnaissance","reason":"The line restricts approval from rapid audits unless release gates are satisfied. It is governance guidance, not reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:references/depth-and-profiles.md:20:system-reconnaissance","reason":"The line requires an independent challenger for deeper audits. It does not gather system information.","verdict":"false_positive","confidence":1},{"id":"network:references/schemas/audit-manifest.schema.json:2:hardcoded-url","reason":"The URL is the standard JSON Schema dialect identifier in a $schema field. It does not initiate a network request.","verdict":"false_positive","confidence":1},{"id":"network:references/schemas/evidence.schema.json:2:hardcoded-url","reason":"The URL identifies the JSON Schema dialect and is passive metadata. No code fetches or transmits data to it.","verdict":"false_positive","confidence":1},{"id":"network:references/schemas/finding.schema.json:2:hardcoded-url","reason":"This is a conventional JSON Schema dialect URI, not an outbound endpoint. The schema contains no network execution.","verdict":"false_positive","confidence":1},{"id":"network:references/schemas/selected-controls.schema.json:2:hardcoded-url","reason":"The hardcoded value is a JSON Schema dialect identifier. It is descriptive metadata and causes no network access.","verdict":"false_positive","confidence":1},{"id":"blocker:references/schemas/selected-controls.schema.json:14:system-reconnaissance","reason":"The line documents a denominator field used for audit coverage calculations. It performs no system inspection.","verdict":"false_positive","confidence":1},{"id":"blocker:references/templates/intake-template.md:9:system-reconnaissance","reason":"The line asks the operator to select an audit depth tier. It does not enumerate a host, network, or environment.","verdict":"false_positive","confidence":1},{"id":"blocker:references/templates/report-template.md:37:system-reconnaissance","reason":"The line is a report placeholder for evidence coverage. It contains no executable or reconnaissance behavior.","verdict":"false_positive","confidence":1},{"id":"filesystem:scripts/score.py:352:python-file-write-append","reason":"The scorer writes its documented score sheet to the operator-provided --out path. This is expected artifact generation with no hidden path or data access.","verdict":"false_positive","confidence":0.98},{"id":"blocker:scripts/score.py:129:system-reconnaissance","reason":"The line reads a control identifier from already supplied audit data. It performs no system discovery.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/score.py:130:system-reconnaissance","reason":"The line checks whether a control identifier belongs to a fixed gate-control set. It has no reconnaissance capability.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/score.py:134:system-reconnaissance","reason":"The line checks a control identifier against a static category map. This is local scoring logic, not system inspection.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/score.py:261:system-reconnaissance","reason":"The line exits with a validation error for an invalid status. It neither discovers system details nor executes an external tool.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/score.py:320:system-reconnaissance","reason":"The cited text is a source comment about a rapid-audit coverage denominator. It has no operational behavior.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/score.py:370:system-reconnaissance","reason":"The line formats two computed coverage percentages for display. It does not inspect a system or network.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:11:ruby-shell-backtick-execution","reason":"Backticks format a bundled specification path in Markdown. They are not Ruby backticks or executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"Backticks format example dependency filenames in prose. The line asks for authorized project context and contains no shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks identify a local intake template path in Markdown. No command is executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The line references a local profile guide using Markdown code formatting. It is audit setup guidance, not command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The backticks format an audit identifier template. The text is a naming convention and cannot execute.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The backticks format fixed control identifiers. The line enforces scope and authorization gates rather than invoking external commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The line documents a local artifact directory and a bundled initializer with explicit arguments. Markdown backticks are not execution, and the initializer refuses overwrites.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The backticks format an expected local artifact filename and schema path. No external command appears on this line.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The backticks format a local documentation path. The instruction concerns evidence collection and has no shell behavior.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks identify a local evidence artifact. They are Markdown formatting and do not invoke a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The backticks label an unverified audit status. The line limits unsupported claims and contains no executable command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The backticks format the findings artifact name. The line describes report generation rather than shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The line introduces the bundled scoring script using Markdown formatting. The actual invocation is explicit and local, with no dynamic shell construction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The cited line begins a fenced example command block. A Markdown fence is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The range contains the end of a documented local scorer invocation and its Markdown fence. Arguments are explicit and no untrusted shell interpolation is used.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks format a verification-log artifact name. The line records review outcomes and does not execute a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The backticks format local report and template paths. This is artifact-rendering guidance, not shell backtick execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The line lists required local audit artifact filenames using Markdown formatting. It contains no executable expression.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:24:system-reconnaissance","reason":"The line declares engagement metadata such as depth and access level. It does not perform system reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:28:system-reconnaissance","reason":"The line creates a scoped local artifact directory through a bundled initializer. This is transparent setup, not system discovery.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:32:system-reconnaissance","reason":"The line selects controls from a bundled catalog according to the chosen tier. It does not enumerate the host or environment.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:63:system-reconnaissance","reason":"The line explains deterministic scoring and release-gate evaluation. No reconnaissance behavior is present.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:68:system-reconnaissance","reason":"The line requests an independent contradiction review of audit findings. It does not collect system information.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:68:network-reconnaissance","reason":"The cited contradiction-pass instruction does not scan or contact a network. It only separates review responsibilities.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:123:system-reconnaissance","reason":"The line is a table header comparing rapid, standard, and deep audit tiers. It has no executable behavior.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:512:system-reconnaissance","reason":"The line includes invalid and adversarial input among authorized quality tests. The specification separately requires scope and rules of engagement.","verdict":"false_positive","confidence":0.99},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:654:system-reconnaissance","reason":"The line defines transparent coverage reporting for rapid audits. It does not inspect a system.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:794:system-reconnaissance","reason":"The line discourages unjustified paid-service recommendations. It contains no reconnaissance instruction.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:856:system-reconnaissance","reason":"The line recommends a common artifact structure for rapid audits. It does not gather system data.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:981:system-reconnaissance","reason":"The line requires independent review of drafted findings. It is an assurance process, not system reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:182:network-reconnaissance","reason":"The line lists CI/CD and release process as intake context. It does not direct network scanning.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:203:network-reconnaissance","reason":"The line lists configuration access among evidence that an operator may grant. It neither obtains access nor scans a network.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:204:network-reconnaissance","reason":"The line lists authorized logs and monitoring access as possible evidence. It contains no network operation.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:246:network-reconnaissance","reason":"The line requires an incident escalation process in the rules of engagement. This is a safety control, not reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:288:network-reconnaissance","reason":"The line names a required evidence-record field. It has no network behavior.","verdict":"false_positive","confidence":1},{"id":"blocker:spec/Universal_Software_Engineering_Audit_Specification.md:640:network-reconnaissance","reason":"The line defines the highest audit score band. It does not contact or enumerate a network.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f4838806900353c20a6899b1cbb5f5bc3a23357a","subject_content_hash":"870bfd2893a4b50a25a368d601ebdc316c234d0a044832a9262e49067a961bf3","subject_tree_hash":"3911574ab963f262e2e43e305146f606ae177845e11add3d8e88e7fb89142753","subject_plugin_path":"skills/glenskii/universal-audit","audit_payload_hash":"27f97523de1df816728cd9016dcc5957","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f4838806900353c20a6899b1cbb5f5bc3a23357a","contentHash":"870bfd2893a4b50a25a368d601ebdc316c234d0a044832a9262e49067a961bf3","treeHash":"3911574ab963f262e2e43e305146f606ae177845e11add3d8e88e7fb89142753","pluginPath":"skills/glenskii/universal-audit","auditPayloadHash":"27f97523de1df816728cd9016dcc5957"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/glenskii-universal-audit/audits/2/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}