{"data":{"skill":{"slug":"internet-court-chaingpt","name":"chaingpt","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/chaingpt/chaingpt","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"30d4cb7f-1da0-4c8b-a9eb-5e169b07723b","skill_id":"b7db1378-6aaa-477f-b091-bd3cc5a62f72","version":1,"content_hash":"e54e2c44407dc8331d72b167cfbfb0b0","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are false positives caused by markdown inline code, documentation links, placeholders, and environment variable examples. The real risks are limited to user-facing setup guidance that installs or runs external code, especially the unpinned AgenticOS clone, install, and start command.","remediation":[{"issue":"Unpinned external repository execution guidance","severity":"medium","suggestion":"Pin the AgenticOS repository to a reviewed commit or release, separate clone, install, and run steps, and require users to review source and dependency lockfiles before execution."},{"issue":"Package installation command lacks verification guidance","severity":"medium","suggestion":"Add guidance to install ChainGPT packages from trusted registries, pin versions, and review package provenance before use in production."},{"issue":"Referenced support files are missing from the package","severity":"low","suggestion":"Include the referenced reference, template, example, pattern, migration, MCP, and mock-server files, or remove claims that the skill can read them."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":68,"line_start":50},{"file":"SKILL.md","line_end":71,"line_start":68},{"file":"SKILL.md","line_end":82,"line_start":71},{"file":"SKILL.md","line_end":85,"line_start":82},{"file":"SKILL.md","line_end":90,"line_start":85},{"file":"SKILL.md","line_end":92,"line_start":90},{"file":"SKILL.md","line_end":99,"line_start":92},{"file":"SKILL.md","line_end":119,"line_start":99},{"file":"SKILL.md","line_end":121,"line_start":119},{"file":"SKILL.md","line_end":128,"line_start":121},{"file":"SKILL.md","line_end":137,"line_start":128},{"file":"SKILL.md","line_end":139,"line_start":137},{"file":"SKILL.md","line_end":146,"line_start":139},{"file":"SKILL.md","line_end":151,"line_start":146},{"file":"SKILL.md","line_end":155,"line_start":151},{"file":"SKILL.md","line_end":157,"line_start":155},{"file":"SKILL.md","line_end":164,"line_start":157},{"file":"SKILL.md","line_end":173,"line_start":164},{"file":"SKILL.md","line_end":174,"line_start":173},{"file":"SKILL.md","line_end":176,"line_start":174},{"file":"SKILL.md","line_end":176,"line_start":176},{"file":"SKILL.md","line_end":184,"line_start":178},{"file":"SKILL.md","line_end":187,"line_start":184},{"file":"SKILL.md","line_end":189,"line_start":187},{"file":"SKILL.md","line_end":193,"line_start":189},{"file":"SKILL.md","line_end":195,"line_start":193},{"file":"SKILL.md","line_end":199,"line_start":195},{"file":"SKILL.md","line_end":201,"line_start":199},{"file":"SKILL.md","line_end":209,"line_start":201},{"file":"SKILL.md","line_end":210,"line_start":209},{"file":"SKILL.md","line_end":211,"line_start":210},{"file":"SKILL.md","line_end":212,"line_start":211},{"file":"SKILL.md","line_end":213,"line_start":212},{"file":"SKILL.md","line_end":214,"line_start":213},{"file":"SKILL.md","line_end":222,"line_start":214},{"file":"SKILL.md","line_end":223,"line_start":222},{"file":"SKILL.md","line_end":224,"line_start":223},{"file":"SKILL.md","line_end":225,"line_start":224},{"file":"SKILL.md","line_end":226,"line_start":225},{"file":"SKILL.md","line_end":227,"line_start":226},{"file":"SKILL.md","line_end":228,"line_start":227},{"file":"SKILL.md","line_end":229,"line_start":228}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":176,"line_start":176},{"file":"SKILL.md","line_end":185,"line_start":185},{"file":"SKILL.md","line_end":323,"line_start":323},{"file":"SKILL.md","line_end":330,"line_start":330},{"file":"SKILL.md","line_end":334,"line_start":334},{"file":"SKILL.md","line_end":335,"line_start":335},{"file":"SKILL.md","line_end":336,"line_start":336},{"file":"SKILL.md","line_end":337,"line_start":337},{"file":"SKILL.md","line_end":338,"line_start":338},{"file":"SKILL.md","line_end":339,"line_start":339},{"file":"SKILL.md","line_end":340,"line_start":340},{"file":"SKILL.md","line_end":341,"line_start":341}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":148,"line_start":148},{"file":"SKILL.md","line_end":166,"line_start":166},{"file":"SKILL.md","line_end":322,"line_start":322},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":148,"line_start":148},{"file":"SKILL.md","line_end":166,"line_start":166},{"file":"SKILL.md","line_end":322,"line_start":322},{"file":"SKILL.md","line_end":322,"line_start":322},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":148,"line_start":148},{"file":"SKILL.md","line_end":166,"line_start":166},{"file":"SKILL.md","line_end":322,"line_start":322}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":41,"line_start":41}],"confidence":0.74,"description":"Python: `pip install chaingpt` (unified package for all products)","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"This line instructs users to run pip install for a public package, which executes package installation from an external registry. It is legitimate setup guidance, but it carries supply-chain risk if followed without review."},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":187,"line_start":184}],"confidence":0.84,"description":"```bash","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The bash quick start clones an external GitHub repository, installs dependencies, and starts it without pinning a commit. This can execute changed third-party code if copied blindly."},{"title":"Unpinned Remote Code Execution Guidance","locations":[{"file":"SKILL.md","line_end":186,"line_start":184}],"confidence":0.86,"description":"The AgenticOS quick start tells users to clone a GitHub repository, install dependencies, and start it without pinning a commit or requiring source review. This can execute changed third-party code if copied directly by an agent or user.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Lines 184-186 contain a direct clone, install, and start command for an external repository. The behavior is explicit, although it appears to be setup guidance rather than hidden malicious intent."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":185,"line_start":185}],"confidence":0.78,"description":"git clone https://github.com/ChainGPT-org/AgenticOS.git && cd AgenticOS","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The hardcoded GitHub URL is used in a clone-and-run setup command for an external project. The network access is expected, but it introduces remote code and dependency trust risk."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":342,"audit_model":"codex","audited_at":"2026-07-10T00:02:32.705+00:00","created_at":"2026-07-10T07:43:47.776474+00:00","static_findings":[{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Base URL:** `https://api.chaingpt.org`","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Auth:** `Authorization: Bearer <API_KEY>` header","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Web3 AI Chatbot & LLM | `@chaingpt/generalchat` | `general_assistant` via `POST /chat/stream` | 0.","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| AI NFT Generator | `@chaingpt/nft` | `POST /nft/generate-image` + 5 more | 1-14.25 credits (model/","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Smart Contract Generator | `@chaingpt/smartcontractgenerator` | `smart_contract_generator` via `PO","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Smart Contract Auditor | `@chaingpt/smartcontractauditor` | `smart_contract_auditor` via `POST /ch","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| AI Crypto News | `@chaingpt/ainews` | `GET /news` | 1 credit per 10 records |","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Python: `pip install chaingpt` (unified package for all products)","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":68,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":82,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":85,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":90,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":92,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> For full parameter reference (context injection, custom tones, blockchain enums, chat history retr","category":"external_commands","line_end":99,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":119,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":121,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> For all endpoints (generate-image, generate-multiple-images, queue, progress, mint, enhancePrompt,","category":"external_commands","line_end":128,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":137,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":139,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Full reference: `reference/smart-contract-generator.md`","category":"external_commands","line_end":146,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":151,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"question: `Audit this contract:\\n\\n${contractSourceCode}`,","category":"external_commands","line_end":155,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":157,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Full reference: `reference/smart-contract-auditor.md`","category":"external_commands","line_end":164,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":173,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"res.data.forEach(a => console.log(`${a.title} — ${a.url}`));","category":"external_commands","line_end":174,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":176,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Free RSS (no auth):** `https://app.chaingpt.org/rssfeeds.xml` (all), `-bitcoin.xml`, `-bnb.xml`, `","category":"external_commands","line_end":176,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Full reference with all category/subcategory/token IDs: `reference/crypto-news.md`","category":"external_commands","line_end":184,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":187,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":189,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Full setup, env vars, webhook config, deployment: `reference/agenticos.md`","category":"external_commands","line_end":193,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2B-parameter model on HuggingFace (`Chain-GPT/Solidity-LLM`), MIT license. 83% compilation success r","category":"external_commands","line_end":195,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":199,"severity":"medium","line_start":195},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":201,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> Full reference: `reference/solidity-llm.md`","category":"external_commands","line_end":209,"severity":"medium","line_start":201},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Build a Web3 AI chatbot\" / \"scaffold a chatbot app\" | `templates/chatbot-app.md` |","category":"external_commands","line_end":210,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Build an NFT minting service\" / \"NFT generation tool\" | `templates/nft-minting-service.md` |","category":"external_commands","line_end":211,"severity":"medium","line_start":210},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Set up contract auditing in CI/CD\" / \"audit pipeline\" | `templates/contract-auditor-ci.md` |","category":"external_commands","line_end":212,"severity":"medium","line_start":211},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Build a crypto news dashboard\" / \"news feed widget\" | `templates/news-dashboard.md` |","category":"external_commands","line_end":213,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Launch an AI Twitter agent\" / \"create a crypto bot\" | `templates/twitter-agent.md` |","category":"external_commands","line_end":214,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Combine multiple products\" / \"multi-product architecture\" | `templates/composition-patterns.md` |","category":"external_commands","line_end":222,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| LLM Chatbot — full API, context injection, tones, enums | `reference/llm-chatbot.md` |","category":"external_commands","line_end":223,"severity":"medium","line_start":222},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| NFT Generator — all endpoints, models, styles, chains | `reference/nft-generator.md` |","category":"external_commands","line_end":224,"severity":"medium","line_start":223},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Smart Contract Generator — params, SDK, history | `reference/smart-contract-generator.md` |","category":"external_commands","line_end":225,"severity":"medium","line_start":224},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Smart Contract Auditor — audit params, SDK, report format | `reference/smart-contract-auditor.md` ","category":"external_commands","line_end":226,"severity":"medium","line_start":225},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Crypto News — categories, tokens, RSS feeds | `reference/crypto-news.md` |","category":"external_commands","line_end":227,"severity":"medium","line_start":226},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| AgenticOS — setup, webhooks, deployment | `reference/agenticos.md` |","category":"external_commands","line_end":228,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Solidity LLM — model specs, training, benchmarks | `reference/solidity-llm.md` |","category":"external_commands","line_end":229,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| SaaS & Whitelabel — launchpad, staking, vesting products | `reference/saas-whitelabel.md` |","category":"external_commands","line_end":230,"severity":"medium","line_start":229},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Pricing — complete credit costs across all products | `reference/pricing.md` |","category":"external_commands","line_end":231,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Error Codes — HTTP errors, SDK exceptions, troubleshooting | `reference/error-codes.md` |","category":"external_commands","line_end":232,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Product Selection — decision matrix, cost estimates by scale | `reference/product-selection.md` |","category":"external_commands","line_end":233,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Wallet Integration — MetaMask, WalletConnect, minting flows | `reference/wallet-integration.md` |","category":"external_commands","line_end":234,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Advanced Patterns — streaming, rate limiting, caching, circuit breaker | `reference/advanced-patte","category":"external_commands","line_end":235,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Deployment — Vercel, Railway, Docker, AWS Lambda, CI/CD | `reference/deployment.md` |","category":"external_commands","line_end":236,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Cost Optimization — caching, batching, history toggle strategies | `reference/cost-optimization.md","category":"external_commands","line_end":237,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| TypeScript Types — complete request/response interfaces | `reference/typescript-types.md` |","category":"external_commands","line_end":241,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Complete runnable examples are in the `examples/` directory:","category":"external_commands","line_end":243,"severity":"medium","line_start":241},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/js/chatbot-stream.js` — Streaming chatbot with context injection","category":"external_commands","line_end":244,"severity":"medium","line_start":243},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/js/nft-generate-mint.js` — Generate image + mint NFT on BSC","category":"external_commands","line_end":245,"severity":"medium","line_start":244},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/js/audit-contract.js` — Audit a Solidity contract file","category":"external_commands","line_end":246,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/js/fetch-news.js` — Fetch filtered crypto news","category":"external_commands","line_end":247,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/python/chatbot_stream.py` — Async streaming chatbot","category":"external_commands","line_end":248,"severity":"medium","line_start":247},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/python/nft_generate_mint.py` — Generate + mint NFT","category":"external_commands","line_end":249,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/python/audit_contract.py` — Audit contract from file","category":"external_commands","line_end":250,"severity":"medium","line_start":249},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/python/fetch_news.py` — Fetch and display news","category":"external_commands","line_end":283,"severity":"medium","line_start":250},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When generating Solidity contracts, check the `patterns/` directory first. 45+ audited patterns avai","category":"external_commands","line_end":284,"severity":"medium","line_start":283},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `patterns/tokens.md` — 10 ERC-20 variants (basic, burnable, taxable, reflection, governance, etc.)","category":"external_commands","line_end":285,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `patterns/nfts.md` — 10 NFT patterns (ERC-721, 721A, lazy mint, soulbound, dynamic, ERC-1155, etc.","category":"external_commands","line_end":286,"severity":"medium","line_start":285},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `patterns/defi.md` — 10 DeFi patterns (staking, vesting, bonding curve, AMM, flash loans, etc.)","category":"external_commands","line_end":287,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `patterns/governance.md` — 5 DAO patterns (Governor, multi-sig, treasury, delegation)","category":"external_commands","line_end":288,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `patterns/security.md` — 10 security patterns (access control, upgradeable, timelock, escrow, etc.","category":"external_commands","line_end":295,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `migration/from-openai.md` — OpenAI → ChainGPT (concept mapping, code migration, pricing compariso","category":"external_commands","line_end":296,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `migration/from-alchemy.md` — Alchemy AI → ChainGPT (complementary + replacement strategies)","category":"external_commands","line_end":297,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `migration/from-custom.md` — Custom AI solutions → ChainGPT (cost comparison, hybrid approach)","category":"external_commands","line_end":305,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/chaingpt-playground` | Interactively test any ChainGPT API endpoint live |","category":"external_commands","line_end":306,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/chaingpt-debug` | Diagnose and fix ChainGPT API errors |","category":"external_commands","line_end":307,"severity":"medium","line_start":306},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/chaingpt-hackathon` | Scaffold a complete hackathon project in 60 seconds |","category":"external_commands","line_end":308,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/chaingpt-update` | Check for and apply skill updates |","category":"external_commands","line_end":312,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the ChainGPT MCP server is installed, Claude can call ChainGPT APIs directly (not just generate c","category":"external_commands","line_end":316,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A full mock server is available at `mock-server/` for development and CI/CD without spending credits","category":"external_commands","line_end":316,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Store API keys in environment variables** — never hardcode. Use `process.env.CHAINGPT_API_KEY` ","category":"external_commands","line_end":322,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Include error handling** — wrap SDK calls in try/catch with product-specific error classes (e.g","category":"external_commands","line_end":325,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"8. **Use patterns for contracts** — check `patterns/` before generating Solidity from scratch.","category":"external_commands","line_end":330,"severity":"medium","line_start":329},{"id":"network:SKILL.md:14:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Base URL:** `https://api.chaingpt.org`","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"network:SKILL.md:17:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Credits:** 1 CGPTc = $0.01 USD (never expire). Purchase at https://app.chaingpt.org/addcredits","category":"network","line_end":17,"severity":"low","line_start":17},{"id":"network:SKILL.md:18:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **API Dashboard:** https://app.chaingpt.org/apidashboard","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:SKILL.md:23:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"1. Visit https://app.chaingpt.org — connect a crypto wallet to sign up","category":"network","line_end":23,"severity":"low","line_start":23},{"id":"network:SKILL.md:86:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -X POST \"https://api.chaingpt.org/chat/stream\" \\","category":"network","line_end":86,"severity":"low","line_start":86},{"id":"network:SKILL.md:176:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Free RSS (no auth):** `https://app.chaingpt.org/rssfeeds.xml` (all), `-bitcoin.xml`, `-bnb.xml`, `","category":"network","line_end":176,"severity":"low","line_start":176},{"id":"network:SKILL.md:185:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"git clone https://github.com/ChainGPT-org/AgenticOS.git && cd AgenticOS","category":"network","line_end":185,"severity":"low","line_start":185},{"id":"network:SKILL.md:323:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"2. **Handle credit exhaustion** — check for HTTP 402/403 and prompt the user to top up at https://ap","category":"network","line_end":323,"severity":"low","line_start":323},{"id":"network:SKILL.md:330:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"9. **Use the mock server for testing** — point to `http://localhost:3001` during development to avoi","category":"network","line_end":330,"severity":"low","line_start":330},{"id":"network:SKILL.md:334:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **API Dashboard:** https://app.chaingpt.org/apidashboard","category":"network","line_end":334,"severity":"low","line_start":334},{"id":"network:SKILL.md:335:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Pricing:** https://app.chaingpt.org/pricing","category":"network","line_end":335,"severity":"low","line_start":335},{"id":"network:SKILL.md:336:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Purchase Credits:** https://app.chaingpt.org/addcredits","category":"network","line_end":336,"severity":"low","line_start":336},{"id":"network:SKILL.md:337:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Grant Program ($1M):** https://www.chaingpt.org/web3-ai-grant","category":"network","line_end":337,"severity":"low","line_start":337},{"id":"network:SKILL.md:338:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Developer Docs:** https://docs.chaingpt.org/dev-docs-b2b-saas-api-and-sdk","category":"network","line_end":338,"severity":"low","line_start":338},{"id":"network:SKILL.md:339:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **Solidity LLM (HuggingFace):** https://huggingface.co/Chain-GPT/Solidity-LLM","category":"network","line_end":339,"severity":"low","line_start":339},{"id":"network:SKILL.md:340:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **AgenticOS (GitHub):** https://github.com/ChainGPT-org/AgenticOS","category":"network","line_end":340,"severity":"low","line_start":340},{"id":"network:SKILL.md:341:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- **SaaS Demo Booking:** https://calendly.com/saaswl/demo","category":"network","line_end":341,"severity":"low","line_start":341},{"id":"env_access:SKILL.md:52:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"const chat = new GeneralChat({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":52,"severity":"low","line_start":52},{"id":"env_access:SKILL.md:101:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"const nft = new Nft({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":101,"severity":"low","line_start":101},{"id":"env_access:SKILL.md:130:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"const gen = new SmartContractGenerator({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":130,"severity":"low","line_start":130},{"id":"env_access:SKILL.md:148:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"const auditor = new SmartContractAuditor({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:SKILL.md:166:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"const news = new AINews({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":166,"severity":"low","line_start":166},{"id":"env_access:SKILL.md:322:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"1. **Store API keys in environment variables** — never hardcode. Use `process.env.CHAINGPT_API_KEY` ","category":"env_access","line_end":322,"severity":"low","line_start":322},{"id":"env_access:SKILL.md:52:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"const chat = new GeneralChat({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":52,"severity":"low","line_start":52},{"id":"env_access:SKILL.md:101:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"const nft = new Nft({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":101,"severity":"low","line_start":101},{"id":"env_access:SKILL.md:130:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"const gen = new SmartContractGenerator({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":130,"severity":"low","line_start":130},{"id":"env_access:SKILL.md:148:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"const auditor = new SmartContractAuditor({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:SKILL.md:166:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"const news = new AINews({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":166,"severity":"low","line_start":166},{"id":"env_access:SKILL.md:322:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"1. **Store API keys in environment variables** — never hardcode. Use `process.env.CHAINGPT_API_KEY` ","category":"env_access","line_end":322,"severity":"low","line_start":322},{"id":"env_access:SKILL.md:322:python-environment-access","file":"SKILL.md","pattern":"Python environment access","snippet":"1. **Store API keys in environment variables** — never hardcode. Use `process.env.CHAINGPT_API_KEY` ","category":"env_access","line_end":322,"severity":"low","line_start":322},{"id":"env_access:SKILL.md:15:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"- **Auth:** `Authorization: Bearer <API_KEY>` header","category":"env_access","line_end":15,"severity":"high","line_start":15},{"id":"env_access:SKILL.md:52:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"const chat = new GeneralChat({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":52,"severity":"high","line_start":52},{"id":"env_access:SKILL.md:76:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"async with ChainGPTClient(api_key=API_KEY) as client:","category":"env_access","line_end":76,"severity":"high","line_start":76},{"id":"env_access:SKILL.md:87:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"-H \"Authorization: Bearer $CHAINGPT_API_KEY\" \\","category":"env_access","line_end":87,"severity":"high","line_start":87},{"id":"env_access:SKILL.md:101:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"const nft = new Nft({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":101,"severity":"high","line_start":101},{"id":"env_access:SKILL.md:130:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"const gen = new SmartContractGenerator({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":130,"severity":"high","line_start":130},{"id":"env_access:SKILL.md:148:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"const auditor = new SmartContractAuditor({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":148,"severity":"high","line_start":148},{"id":"env_access:SKILL.md:166:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"const news = new AINews({ apiKey: process.env.CHAINGPT_API_KEY });","category":"env_access","line_end":166,"severity":"high","line_start":166},{"id":"env_access:SKILL.md:322:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"1. **Store API keys in environment variables** — never hardcode. Use `process.env.CHAINGPT_API_KEY` ","category":"env_access","line_end":322,"severity":"high","line_start":322},{"id":"sensitive:SKILL.md:52:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"const chat = new GeneralChat({ apiKey: process.env.CHAINGPT_API_KEY });","category":"sensitive","line_end":52,"severity":"high","line_start":52},{"id":"sensitive:SKILL.md:101:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"const nft = new Nft({ apiKey: process.env.CHAINGPT_API_KEY });","category":"sensitive","line_end":101,"severity":"high","line_start":101},{"id":"sensitive:SKILL.md:130:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"const gen = new SmartContractGenerator({ apiKey: process.env.CHAINGPT_API_KEY });","category":"sensitive","line_end":130,"severity":"high","line_start":130},{"id":"sensitive:SKILL.md:148:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"const auditor = new SmartContractAuditor({ apiKey: process.env.CHAINGPT_API_KEY });","category":"sensitive","line_end":148,"severity":"high","line_start":148},{"id":"sensitive:SKILL.md:166:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"const news = new AINews({ apiKey: process.env.CHAINGPT_API_KEY });","category":"sensitive","line_end":166,"severity":"high","line_start":166},{"id":"sensitive:SKILL.md:322:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"1. **Store API keys in environment variables** — never hardcode. Use `process.env.CHAINGPT_API_KEY` ","category":"sensitive","line_end":322,"severity":"high","line_start":322},{"id":"blocker:SKILL.md:297:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `migration/from-custom.md` — Custom AI solutions → ChainGPT (cost comparison, hybrid approach)","category":"blocker","line_end":297,"severity":"low","line_start":297},{"id":"blocker:SKILL.md:330:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"9. **Use the mock server for testing** — point to `http://localhost:3001` during development to avoi","category":"blocker","line_end":330,"severity":"low","line_start":330}],"finding_verdicts":[{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"This line instructs users to run pip install for a public package, which executes package installation from an external registry. It is legitimate setup guidance, but it carries supply-chain risk if followed without review.","verdict":"confirmed","severity":"medium","confidence":0.74},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"The bash quick start clones an external GitHub repository, installs dependencies, and starts it without pinning a commit. This can execute changed third-party code if copied blindly.","verdict":"confirmed","severity":"medium","confidence":0.84},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:195:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:201:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:222:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:226:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:283:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:SKILL.md:329:ruby-shell-backtick-execution","reason":"This finding is caused by markdown backticks, code fences, package names, endpoints, or file references in documentation. It is not Ruby or shell backtick execution by the skill itself.","verdict":"false_positive","confidence":0.91},{"id":"network:SKILL.md:14:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:17:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:18:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:23:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:86:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:176:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:185:hardcoded-url","reason":"The hardcoded GitHub URL is used in a clone-and-run setup command for an external project. The network access is expected, but it introduces remote code and dependency trust risk.","verdict":"confirmed","severity":"low","confidence":0.78},{"id":"network:SKILL.md:323:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:330:hardcoded-url","reason":"The URL points to localhost for a mock server during development, not to an external service or reconnaissance target. It does not exfiltrate data.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:334:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:335:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:336:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:337:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:338:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:339:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:340:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:341:hardcoded-url","reason":"The URL is an advertised ChainGPT API, dashboard, documentation, RSS, or product link used as integration documentation. No hidden or unauthorized network call is present in the skill itself.","verdict":"false_positive","confidence":0.93},{"id":"env_access:SKILL.md:52:environment-variable-access-dot-notation","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:101:environment-variable-access-dot-notation","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:130:environment-variable-access-dot-notation","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:148:environment-variable-access-dot-notation","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:166:environment-variable-access-dot-notation","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:322:environment-variable-access-dot-notation","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:52:environment-variable-object","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:101:environment-variable-object","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:130:environment-variable-object","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:148:environment-variable-object","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:166:environment-variable-object","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:322:environment-variable-object","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:322:python-environment-access","reason":"The process.env or os.environ reference appears only in example code and secret-handling guidance. It reads the expected ChainGPT key name and does not expose or transmit unrelated environment data.","verdict":"false_positive","confidence":0.94},{"id":"env_access:SKILL.md:15:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:52:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:76:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:87:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:101:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:130:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:148:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:166:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:322:generic-api-secret-keys","reason":"The snippet uses an API key placeholder or environment variable name in documentation, not a real embedded secret. The surrounding guidance tells users to store keys securely rather than hardcode them.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:SKILL.md:52:environment-file-access","reason":"The snippet references process.env.CHAINGPT_API_KEY in documentation, not direct .env file access or bulk secret harvesting. It is a safe secret-handling example for an API integration skill.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:SKILL.md:101:environment-file-access","reason":"The snippet references process.env.CHAINGPT_API_KEY in documentation, not direct .env file access or bulk secret harvesting. It is a safe secret-handling example for an API integration skill.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:SKILL.md:130:environment-file-access","reason":"The snippet references process.env.CHAINGPT_API_KEY in documentation, not direct .env file access or bulk secret harvesting. It is a safe secret-handling example for an API integration skill.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:SKILL.md:148:environment-file-access","reason":"The snippet references process.env.CHAINGPT_API_KEY in documentation, not direct .env file access or bulk secret harvesting. It is a safe secret-handling example for an API integration skill.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:SKILL.md:166:environment-file-access","reason":"The snippet references process.env.CHAINGPT_API_KEY in documentation, not direct .env file access or bulk secret harvesting. It is a safe secret-handling example for an API integration skill.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:SKILL.md:322:environment-file-access","reason":"The snippet references process.env.CHAINGPT_API_KEY in documentation, not direct .env file access or bulk secret harvesting. It is a safe secret-handling example for an API integration skill.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:297:system-reconnaissance","reason":"The text describes migration guidance or a localhost mock server, not system reconnaissance. There is no instruction to enumerate host details, credentials, or internal network state.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:330:system-reconnaissance","reason":"The text describes migration guidance or a localhost mock server, not system reconnaissance. There is no instruction to enumerate host details, credentials, or internal network state.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Unpinned Remote Code Execution Guidance","severity":"medium","locations":[{"file":"SKILL.md","line_end":186,"line_start":184}],"confidence":0.86,"description":"The AgenticOS quick start tells users to clone a GitHub repository, install dependencies, and start it without pinning a commit or requiring source review. This can execute changed third-party code if copied directly by an agent or user.","confidence_reasoning":"Lines 184-186 contain a direct clone, install, and start command for an external repository. The behavior is explicit, although it appears to be setup guidance rather than hidden malicious intent."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}