{"data":{"skill":{"slug":"humanleap-tradehand","name":"tradehand","icon":"📦","repo":"https://github.com/humanleap/agent-skills/tree/1eaefe1e9bc4f006ccce55793eb98055619e9a5d/skills/tradehand","status":"approved","author":"humanleap","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"610c4a10-4854-404b-926c-4bacf0aea65c","skill_id":"6bf2ceba-9ab1-4081-b241-c550422e7df9","version":1,"content_hash":"v3:f34d6380f82ea59b1965530a3bc0b1bc54c25f91:751aa286567e7905b8402511a0cd632af434a2163a9c86bec21af4721e042370:173cdfe047d262fca47b96c71f7f42f59057faab1bc49fc395d0077cc1bda94b:736b696c6c732f68756d616e6c6561702f747261646568616e64:14ff66d5d151519a4220cdd7a900ac09","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 22 static findings are false positives involving Markdown formatting, documented setup, service links, and payment verification guidance. The skill requires customer authentication, exact booking approval, and server-confirmed payment status. No evidence found of prompt injection, credential exfiltration, or system reconnaissance in the reviewed file; external services were not audited.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":70,"audit_model":"codex","audited_at":"2026-10-03T13:12:31.947+00:00","created_at":"2026-10-03T14:02:56.030883+00:00","static_findings":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill tradehand`. Connect remo","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Respect public versus customer access.** Public search does not authorise a booking. Inspect `t","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **A checkout link is not payment.** Report paid status only when `get_job` confirms it.","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Find the trade and area.** Use `browse_trades` and `search_traders` with the user's job and loc","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Inspect the listing.** Use `get_trader` and `get_service_options`. Retain the exact returned li","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Prepare a booking when customer tools are available.** Call `prepare_booking` with the listing ","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Get the review.** Call `confirm_booking` with `expectedRevision` and the chosen `slotReference`","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Commit the approved booking.** After the customer says yes, call `confirm_booking` again with t","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Check the result.** Read `get_job` for the booking/payment status. On `SLOT_UNAVAILABLE` or `ST","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `browse_trades`, `search_traders` | Find public listings for a trade and area. |","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `get_trader`, `get_service_options` | Inspect a real trader and the service choices. |","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `prepare_booking`, `confirm_booking` | Customer booking preparation, price review and approved com","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `quote_start`, `quote_answer`, other advertised `quote_*` tools | Price work with no fixed-price s","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `list_my_jobs`, `get_job` | Inspect the signed-in customer's jobs and status. |","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `start_job_checkout` | Prepare a payment link for an amount due on a job. |","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"network:SKILL.md:4:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"homepage\":\"https://tradehand.com\",\"openclaw\":{\"emoji\":\"🛠️\",\"requires\":{\"bins\":[],\"env\":","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill tradehand`. Connect remo","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:56:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Public directory and customer site: https://tradehand.com","category":"network","line_end":56,"severity":"low","line_start":56},{"id":"network:SKILL.md:57:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Existing customer plugin: https://github.com/Humanleap/tradehand-agent-plugin","category":"network","line_end":57,"severity":"low","line_start":57},{"id":"network:SKILL.md:58:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Public/customer MCP: https://tradehand.com/api/mcp and https://tradehand.com/api/mcp/chatgpt","category":"network","line_end":58,"severity":"low","line_start":58},{"id":"blocker:SKILL.md:20:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"4. **A checkout link is not payment.** Report paid status only when `get_job` confirms it.","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:SKILL.md:65:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Do not state that money was paid from a checkout URL or redirect alone.","category":"blocker","line_end":65,"severity":"low","line_start":65}],"finding_verdicts":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"Backticks format an explicit skill installation command and MCP URLs in Markdown, not Ruby or shell command substitution. No hidden execution or injected arguments appear.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The backticks format tools/list, an MCP capability discovery operation, rather than executable shell syntax. The instruction requires authentication before private customer operations.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The backticks identify the get_job tool in prose, not a shell expression. The instruction prevents false payment claims by requiring server confirmation.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticks format browse_trades and search_traders as MCP tool names. The documented action searches public listings using supported job and location filters.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticks format listing inspection tool names within Markdown instructions. Preserving returned listing and service identifiers does not execute a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks identify prepare_booking and returned fields, not command substitution. Customer-supplied address data serves the stated booking purpose behind customer authentication.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The backticks format confirm_booking and its revision and slot fields. This first call produces a review without booking, preserving customer approval.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backticks format MCP operation and response field names, not shell code. Booking commitment requires customer approval of the exact reviewed amount.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The backticks format get_job and server error identifiers within prose. Changed booking details require renewed preparation and customer approval.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"This Markdown table labels public directory search tools with inline code formatting. It contains no shell or Ruby execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"This Markdown table labels trader and service inspection tools with inline code formatting. No executable shell expression appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The table documents booking tool names rather than shell commands. Its stated purpose includes price review and approved commitment.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The table formats quote tool identifiers and the advertised quote_* family in Markdown. The asterisk describes tool naming, not a shell wildcard operation.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks format customer job inspection tool names. Access is explicitly limited to the signed-in customer's jobs, not operating system information.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The table documents start_job_checkout as a payment link preparation tool. Inline Markdown formatting does not execute a shell or charge a customer.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:4:hardcoded-url","reason":"The HTTPS URL is homepage metadata for the service the skill explicitly targets. It does not encode a network request or transmit credentials.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The URLs are explicit Tradehand MCP connection endpoints for the advertised service. No unrelated recipient or concealed data transmission appears in the setup instructions.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:56:hardcoded-url","reason":"This supporting resource links to the Tradehand directory and customer site. A relevant reference URL alone provides no evidence of malicious network activity.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:57:hardcoded-url","reason":"The GitHub URL is a labeled customer plugin resource under the same author organization. The line neither executes repository content nor sends user data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:58:hardcoded-url","reason":"The listed HTTPS endpoints repeat the documented Tradehand public and customer MCP integrations. Their stated purpose matches the skill, with no exfiltration destination shown.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:20:system-reconnaissance","reason":"This line requires get_job confirmation before reporting payment. It inspects application transaction status, not host information or system resources.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:65:system-reconnaissance","reason":"This line prohibits inferring payment from checkout links or redirects. It contains no instruction to inspect a host, enumerate users, or discover system configuration.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","subject_content_hash":"751aa286567e7905b8402511a0cd632af434a2163a9c86bec21af4721e042370","subject_tree_hash":"173cdfe047d262fca47b96c71f7f42f59057faab1bc49fc395d0077cc1bda94b","subject_plugin_path":"skills/humanleap/tradehand","audit_payload_hash":"14ff66d5d151519a4220cdd7a900ac09","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","contentHash":"751aa286567e7905b8402511a0cd632af434a2163a9c86bec21af4721e042370","treeHash":"173cdfe047d262fca47b96c71f7f42f59057faab1bc49fc395d0077cc1bda94b","pluginPath":"skills/humanleap/tradehand","auditPayloadHash":"14ff66d5d151519a4220cdd7a900ac09"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/humanleap-tradehand/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}