{"data":{"skill":{"slug":"humanleap-bot-store-marketplace","name":"bot-store-marketplace","icon":"📦","repo":"https://github.com/humanleap/agent-skills/tree/1eaefe1e9bc4f006ccce55793eb98055619e9a5d/skills/bot-store-marketplace","status":"approved","author":"humanleap","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"a1f74bfd-1f25-44d7-9e3b-aeb5e2928160","skill_id":"c7bc1676-c116-4c18-b12b-2727e54cc151","version":1,"content_hash":"v3:f34d6380f82ea59b1965530a3bc0b1bc54c25f91:d6fdf25baf2568f940f77f5c29b242f91a24a52bf2255e6bbc05aa5844944214:5f50e92601b1b4a5dc26ac2cd1796e61342d34f80fffe8d4b14e4100dbe46efd:736b696c6c732f68756d616e6c6561702f626f742d73746f72652d6d61726b6574706c616365:fe4bb6d7b637b5f470c42c16ad0e2c7c","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"One finding is confirmed: the installation command executes an unpinned external package and retrieves upstream skill content without an immutable reference. Sixteen findings are false positives involving Markdown tool names, task-related URLs, and checkout terminology. No evidence found of prompt injection, credential collection, unauthorized payment, or system reconnaissance in the reviewed skill.","remediation":[{"issue":"The installation command executes an unpinned package and retrieves skill content without an immutable upstream reference.","severity":"medium","suggestion":"Pin and verify the installer version and upstream revision, review retrieved content, and request explicit user approval before installation."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":13,"line_start":13}],"confidence":0.96,"description":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill bot-store-marketplace`. ","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The backticks are Markdown, but the enclosed pnpm dlx installation command executes an unpinned external package and retrieves upstream skill content. This creates a concrete supply-chain execution risk, although no malicious payload is shown."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":63,"audit_model":"codex","audited_at":"2026-10-03T12:54:33.076+00:00","created_at":"2026-10-03T14:02:23.728676+00:00","static_findings":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill bot-store-marketplace`. ","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Search the task.** Call `search_bots` with a short capability query and the constraints support","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Inspect a candidate.** Call `get_bot` with its exact returned slug. Compare facts supplied by t","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Open a free bot.** Share its returned `openInGrokUrl`, or open it when the user requests that a","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Prepare the selected paid bot.** State the returned price, converting GBP pence to pounds. Call","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Hand off checkout.** Give the returned `checkoutUrl` to the human. Payment approval happens the","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `search_bots` | Find templates for the requested task. |","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `get_bot` | Read one exact marketplace listing. |","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `start_bot_purchase` | Prepare the chosen listing's safe checkout handoff. |","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"network:SKILL.md:4:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"homepage\":\"https://bot.store\",\"openclaw\":{\"emoji\":\"🤖\",\"requires\":{\"bins\":[],\"env\":[]}}}","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill bot-store-marketplace`. ","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:50:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Marketplace: https://bot.store","category":"network","line_end":50,"severity":"low","line_start":50},{"id":"network:SKILL.md:51:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- MCP: https://bot.store/mcp","category":"network","line_end":51,"severity":"low","line_start":51},{"id":"network:SKILL.md:52:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Existing Grok plugin: https://github.com/Humanleap/bot-store-grok-plugin","category":"network","line_end":52,"severity":"low","line_start":52},{"id":"blocker:SKILL.md:20:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"4. **Verify status before claiming success.** Installing this skill is free; it does not buy or inst","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:SKILL.md:31:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"4. **Prepare the selected paid bot.** State the returned price, converting GBP pence to pounds. Call","category":"blocker","line_end":31,"severity":"low","line_start":31},{"id":"blocker:SKILL.md:56:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- A paid result's checkout URL is not its protected Grok link.","category":"blocker","line_end":56,"severity":"low","line_start":56}],"finding_verdicts":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The backticks are Markdown, but the enclosed pnpm dlx installation command executes an unpinned external package and retrieves upstream skill content. This creates a concrete supply-chain execution risk, although no malicious payload is shown.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticks format the public MCP tool name search_bots, not a shell expression. The instruction searches marketplace listings using the requested constraints.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticks format get_bot, a documented marketplace lookup tool. The returned slug is a lookup argument, with no shell evaluation instructed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks format the returned field openInGrokUrl, not executable code. The skill shares the free bot link or opens it upon user request.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The backticks identify start_bot_purchase, an MCP checkout preparation tool rather than a shell command. The skill requires the user's exact bot selection and states that preparation does not charge.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backticks format checkoutUrl, a returned field shared with the human. Payment approval remains on checkout, and no shell execution is instructed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"This table row documents the search_bots tool using Markdown inline code. It contains no shell syntax or execution instruction.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"This table row documents the get_bot lookup tool using Markdown inline code. It contains no shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"This table row names start_bot_purchase and describes checkout handoff preparation. Markdown backticks do not execute the tool or a shell command.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:4:hardcoded-url","reason":"The URL is homepage metadata for the marketplace named in the skill. It does not instruct a request or transmit sensitive data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The HTTPS MCP endpoint supports the explicitly requested bot.store workflow, and the public tools require no credentials. No unrelated destination or secret transmission is instructed.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:50:hardcoded-url","reason":"This supporting resource links to the intended marketplace homepage. No executable request or data exfiltration is shown.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:51:hardcoded-url","reason":"This supporting resource lists the same task-related MCP endpoint documented in installation. A resource link alone is not evidence of harmful network activity.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:52:hardcoded-url","reason":"This is a GitHub reference to an existing Grok plugin, not an instruction to execute or install it. No sensitive data transfer is specified.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:20:system-reconnaissance","reason":"Status verification concerns purchase and installation claims, not host enumeration. The rule prevents falsely claiming that skill installation buys a paid bot.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:31:system-reconnaissance","reason":"This step states a listing price and prepares checkout only for a user-selected bot. It requests no system information or reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:56:system-reconnaissance","reason":"This warning distinguishes a checkout URL from a protected Grok link. It does not instruct probing the system or bypassing access controls.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","subject_content_hash":"d6fdf25baf2568f940f77f5c29b242f91a24a52bf2255e6bbc05aa5844944214","subject_tree_hash":"5f50e92601b1b4a5dc26ac2cd1796e61342d34f80fffe8d4b14e4100dbe46efd","subject_plugin_path":"skills/humanleap/bot-store-marketplace","audit_payload_hash":"fe4bb6d7b637b5f470c42c16ad0e2c7c","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","contentHash":"d6fdf25baf2568f940f77f5c29b242f91a24a52bf2255e6bbc05aa5844944214","treeHash":"5f50e92601b1b4a5dc26ac2cd1796e61342d34f80fffe8d4b14e4100dbe46efd","pluginPath":"skills/humanleap/bot-store-marketplace","auditPayloadHash":"fe4bb6d7b637b5f470c42c16ad0e2c7c"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/humanleap-bot-store-marketplace/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}