{"data":{"skill":{"slug":"internet-court-genvm-lint","name":"genvm-lint","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/genlayer/genvm-lint","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"3d220618-6474-42ce-9121-c2f94a764442","skill_id":"7078c670-feca-496e-bcd7-8a1e60938c19","version":1,"content_hash":"b23fa3b08ee11beed65552e2b66d7823","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The static backtick detections are Markdown documentation and examples, not Ruby or shell backtick execution. No prompt injection, data exfiltration intent, or system reconnaissance evidence was found in the reviewed files.","remediation":[{"issue":"Unpinned package installation guidance","severity":"medium","suggestion":"Recommend installing genvm-linter from a pinned project requirements file or a verified version before running the skill."},{"issue":"Artifact download guidance is minimal","severity":"low","suggestion":"Document the expected source and verification approach for genvm-lint download before agents pre-download SDK artifacts."},{"issue":"Broad Bash tool permission","severity":"low","suggestion":"Keep agent usage limited to explicit genvm-lint commands and contract paths supplied by the user."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":19,"line_start":17},{"file":"SKILL.md","line_end":23,"line_start":19},{"file":"SKILL.md","line_end":25,"line_start":23},{"file":"SKILL.md","line_end":27,"line_start":25},{"file":"SKILL.md","line_end":29,"line_start":27},{"file":"SKILL.md","line_end":34,"line_start":29},{"file":"SKILL.md","line_end":37,"line_start":34},{"file":"SKILL.md","line_end":40,"line_start":37},{"file":"SKILL.md","line_end":42,"line_start":40},{"file":"SKILL.md","line_end":45,"line_start":42},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"SKILL.md","line_end":50,"line_start":46},{"file":"SKILL.md","line_end":52,"line_start":50},{"file":"SKILL.md","line_end":55,"line_start":52},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":65,"line_start":61},{"file":"SKILL.md","line_end":68,"line_start":65},{"file":"SKILL.md","line_end":72,"line_start":68},{"file":"SKILL.md","line_end":77,"line_start":72},{"file":"SKILL.md","line_end":81,"line_start":77},{"file":"SKILL.md","line_end":86,"line_start":81},{"file":"SKILL.md","line_end":91,"line_start":86},{"file":"SKILL.md","line_end":93,"line_start":91},{"file":"SKILL.md","line_end":94,"line_start":93},{"file":"SKILL.md","line_end":96,"line_start":94},{"file":"SKILL.md","line_end":100,"line_start":96},{"file":"SKILL.md","line_end":101,"line_start":100},{"file":"SKILL.md","line_end":102,"line_start":101},{"file":"SKILL.md","line_end":103,"line_start":102},{"file":"SKILL.md","line_end":108,"line_start":103},{"file":"SKILL.md","line_end":111,"line_start":108}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":119,"audit_model":"codex","audited_at":"2026-07-09T23:47:04.404+00:00","created_at":"2026-07-10T07:43:49.331361+00:00","static_findings":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Requires `genvm-linter` (included in `requirements.txt` for boilerplate projects):","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":19,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":23,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Always lint before testing.** Run `genvm-lint check` after writing or modifying a contract. Fix al","category":"external_commands","line_end":25,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":27,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":29,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`check` runs both lint (AST safety) and validate (SDK semantics) in one pass.","category":"external_commands","line_end":34,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":37,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":40,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":42,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":45,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Forbidden imports (`os`, `sys`, `subprocess`, `random`, etc.)","category":"external_commands","line_end":45,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Non-deterministic patterns (bare `float` usage)","category":"external_commands","line_end":50,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":52,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":55,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Types exist in SDK (`TreeMap`, `DynArray`, `Address`, etc.)","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Decorators correctly applied (`@gl.public.view`, `@gl.public.write`)","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Storage fields have valid types (no `dict`/`list`)","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":65,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":68,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":72,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":77,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":81,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":86,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":91,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":93,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### JSON (`--json`)","category":"external_commands","line_end":94,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":96,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":100,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `0` — All checks passed","category":"external_commands","line_end":101,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `1` — Lint or validation errors found","category":"external_commands","line_end":102,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `2` — Contract file not found","category":"external_commands","line_end":103,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `3` — SDK download failed","category":"external_commands","line_end":108,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Run `genvm-lint check contract.py --json`","category":"external_commands","line_end":111,"severity":"medium","line_start":108},{"id":"blocker:SKILL.md:57:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Storage fields have valid types (no `dict`/`list`)","category":"blocker","line_end":57,"severity":"low","line_start":57}],"finding_verdicts":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"This line uses inline Markdown backticks around a package name and requirements file. It is documentation text, not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence documenting an explicit package installation step. It is not hidden Ruby backtick execution or dynamically constructed shell code.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"This line closes a Markdown code fence. It contains no executable instruction beyond the documented setup example.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This line uses inline Markdown backticks for the genvm-lint check command. The command is a visible linter workflow, not obfuscated or dynamic execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence before a documented linter command. The fenced example is explicit and does not interpolate untrusted input into a shell expression.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"This line closes a Markdown code fence. It is not code that would execute in Ruby or a shell.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The inline backticks mark the check subcommand in prose. They do not create a shell execution path.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence for the recommended command examples. The block documents direct genvm-lint invocations with explicit arguments.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"This line closes a Markdown command block. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence for the lint command example. It documents normal CLI use and contains no dynamic shell construction.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"This line closes a Markdown code fence. It does not execute a command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The inline backticks list forbidden Python import names in documentation. They are examples of checks, not executable shell syntax.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The inline backticks mark the Python float type in prose. This is not a command execution construct.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence for the validate command example. It documents a fixed linter subcommand rather than executing hidden code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"This line closes a Markdown command block. It is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The inline backticks identify SDK type names in prose. They do not run commands or evaluate code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The inline backticks identify GenLayer decorators in prose. They are documentation tokens, not shell execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The inline backticks identify Python container type names. This is a validation rule description, not command execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence for schema extraction examples. The examples are explicit genvm-lint commands and not dynamic backtick execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"This line closes a Markdown command block. It contains no executable shell syntax.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence for typecheck examples. The commands are explicit lint tooling commands, not injected shell expressions.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"This line closes a Markdown command block. It is not code that executes.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence for optional artifact download examples. The commands are visible linter subcommands, not hidden Ruby backtick execution.","verdict":"false_positive","confidence":0.86},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This line closes a Markdown command block. It does not perform command execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"This is a Markdown output fence showing human-readable results. It is sample output, not an executable command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"This line closes a Markdown output block. It has no command execution semantics.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The inline backticks mark the --json option in a heading. This is documentation formatting, not executable shell syntax.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"This is a Markdown JSON fence for sample machine-readable output. It is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"This line closes a Markdown JSON block. It contains no executable instruction.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The inline backticks mark an exit code value in documentation. They do not execute code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The inline backticks mark an exit code value in documentation. This is not shell command execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The inline backticks mark an exit code value in documentation. They are not executable syntax.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The inline backticks mark an exit code value in documentation. This is static explanatory text, not a command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The inline backticks show an explicit genvm-lint command in the agent workflow. It is visible user-facing lint tooling, not obfuscated or dynamic execution.","verdict":"false_positive","confidence":0.86},{"id":"blocker:SKILL.md:57:system-reconnaissance","reason":"The words dict and list are Python type names used in a storage validation rule. They do not request system reconnaissance or host inspection.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}