{"data":{"skill":{"slug":"humanleap-sentrydock","name":"sentrydock","icon":"📦","repo":"https://github.com/humanleap/agent-skills/tree/1eaefe1e9bc4f006ccce55793eb98055619e9a5d/skills/sentrydock","status":"approved","author":"humanleap","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"cb71e132-e01a-4c43-86bd-1657d58b4e60","skill_id":"495ebcf7-9c70-4fdb-b69d-74ec67c26780","version":1,"content_hash":"v3:f34d6380f82ea59b1965530a3bc0b1bc54c25f91:19937a1dc601dc8d254596985d98a829ca4f71495eb7f8f0904dd5e533cbce07:c17a8138d11017a2115ec49b27a38effe918bf101e9e11940a3ee4c8949c506c:736b696c6c732f68756d616e6c6561702f73656e747279646f636b:e55f6749bb2ecf0bb77bc0ed2ff20584","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are Markdown formatting, documentation links, legitimate credential configuration, or unrelated prose. Installation executes an unpinned installer and globally installs a remote archive without documented integrity verification, creating supply-chain exposure. No evidence found of credential exfiltration, malicious reconnaissance, or prompt injection in the reviewed skill.","remediation":[{"issue":"Installation executes an unpinned package runner and globally installs a remote archive without documented integrity verification.","severity":"medium","suggestion":"Pin the installer version and publish independently verifiable archive hashes or signatures. Require installation approval, review lifecycle scripts, and prefer isolated installation."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":21,"line_start":17},{"file":"SKILL.md","line_end":23,"line_start":21},{"file":"SKILL.md","line_end":34,"line_start":23},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":42,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":49,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":53,"line_start":52},{"file":"SKILL.md","line_end":61,"line_start":53},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":65,"line_start":65}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":23,"line_start":23}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":13,"line_start":13}],"confidence":0.94,"description":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill sentrydock`. Connect rem","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The documented pnpm dlx command executes the skills package without a version pin, exposing installation to dependency changes. This is supply-chain exposure, not Ruby backtick execution."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":21,"line_start":17}],"confidence":0.95,"description":"```bash","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The fenced example globally installs a remote package archive without documenting integrity verification or lifecycle-script review. Package installation can execute external code with user privileges."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":18,"line_start":18}],"confidence":0.95,"description":"pnpm add -g https://www.sentrydock.com/downloads/sentrydock-1.1.0.tgz","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The URL supplies a package archive directly to a global installation command without a documented hash or signature check. HTTPS alone does not establish package integrity."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":84,"audit_model":"codex","audited_at":"2026-10-03T13:02:51.703+00:00","created_at":"2026-10-03T14:02:39.710544+00:00","static_findings":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill sentrydock`. Connect rem","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":21,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":23,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The CLI uses `SENTRYDOCK_API_KEY` from secure environment configuration. JSON goes to stdout and hel","category":"external_commands","line_end":34,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use OAuth with PKCE and dynamic client registration, or an API key created in Settings → Agents. HTT","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Find news.** Use `news.search` with a topic, time window and limit; use `news.latest` for the n","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Set ongoing monitoring.** Inspect existing monitors first. Review the topic, sources, supported","category":"external_commands","line_end":42,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Read results.** Use `news.mine` and `alerts.list` for monitored hits. Report the saved cadence;","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `account.overview` | Plan, access and limits before starting. |","category":"external_commands","line_end":49,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `news.search`, `news.latest` | Source-linked indexed news. |","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `news.mine`, `news.get` | Account monitor hits or a specific article. |","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `monitors.list`, `monitors.create`, `monitors.update`, `monitors.run` | Inspect and manage authori","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `alerts.list` | Read alerts and recover missed webhook events. |","category":"external_commands","line_end":53,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `delivery.connect` | Connect an authorised delivery destination. |","category":"external_commands","line_end":61,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Agent callback:** use `delivery.connect` with `platform: \"webhook\"` and a public HTTPS destinati","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Follow the API documentation: verify `X-SentryDock-Signature` against HMAC-SHA256 of `X-SentryDock-T","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"network:SKILL.md:4:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"homepage\":\"https://www.sentrydock.com/agents\",\"openclaw\":{\"emoji\":\"📰\",\"requires\":{\"bins","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill sentrydock`. Connect rem","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:18:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"pnpm add -g https://www.sentrydock.com/downloads/sentrydock-1.1.0.tgz","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:SKILL.md:69:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Agent setup: https://www.sentrydock.com/agents","category":"network","line_end":69,"severity":"low","line_start":69},{"id":"network:SKILL.md:70:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- API and delivery rules: https://www.sentrydock.com/api-docs.md","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"network:SKILL.md:71:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- HTTP schema: https://www.sentrydock.com/openapi.json","category":"network","line_end":71,"severity":"low","line_start":71},{"id":"network:SKILL.md:72:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Pricing: https://www.sentrydock.com/pricing","category":"network","line_end":72,"severity":"low","line_start":72},{"id":"env_access:SKILL.md:23:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"The CLI uses `SENTRYDOCK_API_KEY` from secure environment configuration. JSON goes to stdout and hel","category":"env_access","line_end":23,"severity":"high","line_start":23},{"id":"blocker:SKILL.md:28:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. **Search the index honestly.** Search does not crawl the whole web on demand. An empty result doe","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:SKILL.md:30:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"4. **Check the plan and delivery outcome.** News and monitoring need a paid plan. Do not buy one aut","category":"blocker","line_end":30,"severity":"low","line_start":30}],"finding_verdicts":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The documented pnpm dlx command executes the skills package without a version pin, exposing installation to dependency changes. This is supply-chain exposure, not Ruby backtick execution.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The fenced example globally installs a remote package archive without documenting integrity verification or lifecycle-script review. Package installation can execute external code with user privileges.","verdict":"confirmed","severity":"medium","confidence":0.95},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"This location closes a Markdown code fence and introduces a formatted environment-variable name. Neither element is shell command substitution or executable Ruby.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"Backticks format the credential variable and authentication identifiers in documentation. No executable substitution or dynamic command construction appears in this range.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"Backticks delimit an HTTP header, tool identifiers, and a plan error identifier. The paragraph describes authentication and explicitly prohibits sharing real keys.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"news.search and news.latest are Markdown-formatted service tool names. No shell expression or executable backtick syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The text names monitoring tools and requires human review before creation or changes. Backticks are inline formatting, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"news.mine and alerts.list are read-oriented API tool references in prose. Their Markdown delimiters do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The table lists account and news API tool identifiers. These are formatted documentation entries, not executable shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The table documents news.search and news.latest for indexed news retrieval. Inline backticks only format their names.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"news.mine and news.get are table entries describing article retrieval. No shell execution or user-controlled command assembly appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"This table lists monitoring API tools, not shell commands. The surrounding workflow requires human review for monitor creation and changes.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"alerts.list and delivery.connect are Markdown-formatted API identifiers. Reading alerts and connecting an authorized destination are documented service operations, not shell substitutions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"This range documents authorized delivery and webhook configuration. Backticks format tool names and parameters; no executable shell substitution appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"Inline code describes delivery.connect and a webhook parameter, not shell execution. The destination must belong to the user or have authorization.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"Backticks format signature headers, the HMAC input, and an alert tool name. The paragraph specifies webhook verification and replay defenses rather than executing commands.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:4:hardcoded-url","reason":"The URL is a homepage metadata value for the named service. It does not request a network transfer or attach sensitive data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URLs identify the service MCP endpoint and setup page, matching the requested integration. No evidence found of an unrelated collection endpoint or unauthorized credential transmission.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:18:hardcoded-url","reason":"The URL supplies a package archive directly to a global installation command without a documented hash or signature check. HTTPS alone does not establish package integrity.","verdict":"confirmed","severity":"low","confidence":0.95},{"id":"network:SKILL.md:69:hardcoded-url","reason":"This is a supporting link to the service setup page. The line contains no data upload or automatic request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:70:hardcoded-url","reason":"This supporting link points to API and delivery documentation for the named service. No sensitive payload or executable download is specified.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:71:hardcoded-url","reason":"The URL references the service HTTP schema as documentation. No instruction to execute its contents or disclose local data appears.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:72:hardcoded-url","reason":"The line links to pricing information, and the skill prohibits automatic purchases. It does not transmit credentials or initiate payment.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:23:generic-api-secret-keys","reason":"SENTRYDOCK_API_KEY is the documented credential for the intended service, supplied through secure environment configuration. The skill forbids sharing real keys; no unrelated secret collection is shown.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:28:system-reconnaissance","reason":"The line explains news index coverage and cautions against interpreting empty results as proof. It performs no host, process, filesystem, or network reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:30:system-reconnaissance","reason":"The line discusses paid service plans and delivery evidence, explicitly prohibiting automatic purchase. No system information collection or reconnaissance command appears.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","subject_content_hash":"19937a1dc601dc8d254596985d98a829ca4f71495eb7f8f0904dd5e533cbce07","subject_tree_hash":"c17a8138d11017a2115ec49b27a38effe918bf101e9e11940a3ee4c8949c506c","subject_plugin_path":"skills/humanleap/sentrydock","audit_payload_hash":"e55f6749bb2ecf0bb77bc0ed2ff20584","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","contentHash":"19937a1dc601dc8d254596985d98a829ca4f71495eb7f8f0904dd5e533cbce07","treeHash":"c17a8138d11017a2115ec49b27a38effe918bf101e9e11940a3ee4c8949c506c","pluginPath":"skills/humanleap/sentrydock","auditPayloadHash":"e55f6749bb2ecf0bb77bc0ed2ff20584"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/humanleap-sentrydock/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}