{"data":{"skill":{"slug":"internet-court-nansen-token-research","name":"nansen-token-research","icon":"📦","repo":"https://github.com/internet-court/internet-court-skill/tree/main/vendored/nansen/nansen-token-research","status":"approved","author":"internet-court","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"f064adcf-5a7e-4e52-bbbf-99aa6d86e02f","skill_id":"031a042b-446e-4958-b217-d1594b397daa","version":2,"content_hash":"v3:3f6e026a3363e0954ede7bef0cfe88d4475de137:69cf61383f8e07c05110cf547bb6358d6cc381b6d044e6f87925dc6a0b37224e:dfb210957a08a90c938c89302cfc5233b436c7945e01a8f97f87a8c8f8bcc892:736b696c6c732f696e7465726e65742d636f7572742f6e616e73656e2d746f6b656e2d7265736561726368:db6aedbe462ab116f410d2c4b6ef2bbf","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 31 static findings are false positives caused by Markdown code formatting, CLI documentation, and environment-requirement metadata. The skill contains illustrative Nansen CLI queries only; no embedded shell execution, credential handling, reconnaissance, prompt injection, or exfiltration intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":30,"line_start":27},{"file":"SKILL.md","line_end":32,"line_start":30},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":39,"line_start":36},{"file":"SKILL.md","line_end":43,"line_start":39},{"file":"SKILL.md","line_end":47,"line_start":43},{"file":"SKILL.md","line_end":49,"line_start":47},{"file":"SKILL.md","line_end":53,"line_start":49},{"file":"SKILL.md","line_end":55,"line_start":53},{"file":"SKILL.md","line_end":59,"line_start":55},{"file":"SKILL.md","line_end":61,"line_start":59},{"file":"SKILL.md","line_end":65,"line_start":61},{"file":"SKILL.md","line_end":69,"line_start":65},{"file":"SKILL.md","line_end":75,"line_start":69},{"file":"SKILL.md","line_end":76,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":78,"line_start":77},{"file":"SKILL.md","line_end":79,"line_start":78},{"file":"SKILL.md","line_end":80,"line_start":79},{"file":"SKILL.md","line_end":81,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":83,"line_start":82},{"file":"SKILL.md","line_end":84,"line_start":83},{"file":"SKILL.md","line_end":88,"line_start":84},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":90,"line_start":89}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":8,"line_start":8},{"file":"SKILL.md","line_end":11,"line_start":11}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":91,"audit_model":"claude","audited_at":"2026-07-21T03:40:45.364+00:00","created_at":"2026-07-21T03:52:35.141138+00:00","static_findings":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All commands: `nansen research token <sub> [options]`","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`--chain` required for spot endpoints. Use `--token <address>` for token-specific endpoints.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":30,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Timeframes: `1m`, `5m`, `15m`, `30m`, `1h`, `2h`, `4h`, `1d`, `1w`, `1M`","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":39,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":43,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":47,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":49,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`flow-intelligence` breaks down by label: whales, smart traders, exchanges, fresh wallets, public fi","category":"external_commands","line_end":53,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":55,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":59,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":61,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":69,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":75,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--chain` | Required for spot endpoints (ethereum, solana, base, etc.) |","category":"external_commands","line_end":76,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--token` | Token address (alias: `--token-address`) |","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--symbol` | Token symbol for perp endpoints (e.g. BTC) |","category":"external_commands","line_end":78,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--timeframe` | OHLCV interval |","category":"external_commands","line_end":79,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--smart-money` | Filter to SM wallets only (holders) |","category":"external_commands","line_end":80,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--days` | Lookback period (default 30) |","category":"external_commands","line_end":81,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--sort` | Sort field:direction (e.g. `total_pnl_usd:desc`) |","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--fields` | Select specific fields |","category":"external_commands","line_end":83,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--table` | Human-readable table output |","category":"external_commands","line_end":84,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `--format csv` | CSV export |","category":"external_commands","line_end":88,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Perp endpoints use `--symbol` (e.g. BTC), not `--token`.","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `holders --smart-money` returns UNSUPPORTED_FILTER for tokens without SM tracking.","category":"external_commands","line_end":90,"severity":"medium","line_start":89},{"id":"env_access:SKILL.md:8:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"- NANSEN_API_KEY","category":"env_access","line_end":8,"severity":"high","line_start":8},{"id":"env_access:SKILL.md:11:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"primaryEnv: NANSEN_API_KEY","category":"env_access","line_end":11,"severity":"high","line_start":11},{"id":"blocker:SKILL.md:90:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `flow-intelligence` may return all-zero flows for illiquid tokens.","category":"blocker","line_end":90,"severity":"low","line_start":90}],"finding_verdicts":[{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"This is Markdown formatting for documented nansen CLI examples or option names. It does not execute a shell command or construct one from untrusted input.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:8:generic-api-secret-keys","reason":"This metadata declares the API-key prerequisite for the external Nansen CLI. The skill contains no instruction or code that reads, exports, or transmits the key.","verdict":"false_positive","confidence":0.96},{"id":"env_access:SKILL.md:11:generic-api-secret-keys","reason":"This metadata declares the API-key prerequisite for the external Nansen CLI. The skill contains no instruction or code that reads, exports, or transmits the key.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:90:system-reconnaissance","reason":"The text describes an expected empty-data result for illiquid tokens. It contains no host, account, or system discovery action.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"3f6e026a3363e0954ede7bef0cfe88d4475de137","subject_content_hash":"69cf61383f8e07c05110cf547bb6358d6cc381b6d044e6f87925dc6a0b37224e","subject_tree_hash":"dfb210957a08a90c938c89302cfc5233b436c7945e01a8f97f87a8c8f8bcc892","subject_plugin_path":"skills/internet-court/nansen-token-research","audit_payload_hash":"db6aedbe462ab116f410d2c4b6ef2bbf","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"3f6e026a3363e0954ede7bef0cfe88d4475de137","contentHash":"69cf61383f8e07c05110cf547bb6358d6cc381b6d044e6f87925dc6a0b37224e","treeHash":"dfb210957a08a90c938c89302cfc5233b436c7945e01a8f97f87a8c8f8bcc892","pluginPath":"skills/internet-court/nansen-token-research","auditPayloadHash":"db6aedbe462ab116f410d2c4b6ef2bbf"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"unavailable","url":null,"status":null},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"unavailable","verificationState":"not_verified"},"isLatest":true}}