{"data":{"skill":{"slug":"googleworkspace-gws-sheets-append","name":"gws-sheets-append","icon":"📦","repo":"https://github.com/googleworkspace/cli/tree/main/skills/gws-sheets-append/","status":"approved","author":"googleworkspace","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"feb42ae9-ab65-48d8-890a-031d7e85c583","skill_id":"36c52542-fb44-4f32-926b-4cc669c7f9ce","version":2,"content_hash":"55bfb178a2070848a1ca987906cc6dd9","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static command-execution and path-traversal alerts are mostly Markdown false positives from examples and relative documentation links. The real risk is that this community skill instructs the assistant to run a Google Workspace CLI command that writes rows to a spreadsheet, so publication is acceptable with a user-confirmation warning.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":40,"line_start":37},{"file":"SKILL.md","line_end":50,"line_start":49}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":55,"line_start":54}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Spreadsheet Write Operation Through External CLI","locations":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":40,"line_start":37},{"file":"SKILL.md","line_end":50,"line_start":49}],"confidence":0.84,"description":"The skill documents use of the gws command to append rows to a Google Sheets spreadsheet. This is an intended capability, but it can modify cloud data and therefore requires explicit user confirmation before execution.","confidence_reasoning":"The command examples are explicit and the file states that this is a write command. The risk is operational rather than malicious because the caution requires user confirmation."}],"low_findings":[{"title":"Markdown Command Examples Flagged as Execution","locations":[{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":33,"line_start":30},{"file":"SKILL.md","line_end":40,"line_start":37}],"confidence":0.93,"description":"Static analysis reported shell backtick execution, but the matching content is Markdown formatting around usage examples and flag names. No executable script, dynamic command construction, or code runner appears in the reviewed file.","confidence_reasoning":"The relevant lines are inside Markdown code fences, table cells, or inline code spans. There is no Ruby code or shell execution primitive in SKILL.md."},{"title":"Relative Documentation Links Flagged as Path Traversal","locations":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":55,"line_start":54}],"confidence":0.9,"description":"Static analysis reported path traversal because the skill references sibling skill documentation with ../ paths. These are Markdown links and prerequisite reading instructions, not file access code.","confidence_reasoning":"The ../ sequences are present only in Markdown documentation references. No file read, file write, or path concatenation behavior is implemented in this skill file."},{"title":"Weak Cryptography Static Alert Not Supported by Evidence","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":28,"line_start":28}],"confidence":0.95,"description":"Static analysis reported weak cryptographic algorithm patterns at the description line and flag table header. No evidence found of MD5, SHA1, DES, or any cryptographic operation in the reviewed file.","confidence_reasoning":"The cited lines contain a plain description and a Markdown table header. They do not contain cryptographic API names or algorithm selections."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":56,"audit_model":"codex","audited_at":"2026-06-30T01:58:52.539+00:00","created_at":"2026-06-30T03:13:55.538115+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}