{"data":{"skill":{"slug":"jckjhns-skill-check","name":"skill-check","icon":"📦","repo":"https://github.com/JckJhns/skill-check/tree/main/","status":"approved","author":"JckJhns","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"e9b787a9-004f-4dd5-a211-fc3ef1529896","skill_id":"ffa345ec-31f7-4ba6-b05c-c5d3a78f5037","version":5,"content_hash":"3db5cfb9d353e8f849bf4b9b21e4eadc","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"failed","agent_auto_install_policy":"blocked","manual_install_policy":"allowed_with_warning","summary":"AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.","remediation":[],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"evals/evals.json","line_end":60,"line_start":60},{"file":"evals/evals.json","line_end":67,"line_start":67},{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":27,"line_start":27},{"file":"references/quick-check.md","line_end":300,"line_start":300},{"file":"references/standard-check.md","line_end":124,"line_start":124}]},{"factor":"filesystem","evidence":[{"file":"evals/files/broken-skill/scripts/convert.py","line_end":15,"line_start":15},{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":16,"line_start":16},{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":32,"line_start":32},{"file":"README.md","line_end":46,"line_start":46},{"file":"README.md","line_end":46,"line_start":46},{"file":"references/finding-the-skill.md","line_end":31,"line_start":31},{"file":"references/finding-the-skill.md","line_end":31,"line_start":31},{"file":"references/mock-files.md","line_end":59,"line_start":59},{"file":"references/mock-files.md","line_end":60,"line_start":60},{"file":"references/mock-files.md","line_end":61,"line_start":61},{"file":"references/mock-files.md","line_end":62,"line_start":62},{"file":"references/mock-files.md","line_end":63,"line_start":63},{"file":"references/mock-files.md","line_end":98,"line_start":98},{"file":"references/mock-files.md","line_end":135,"line_start":135},{"file":"references/mock-files.md","line_end":157,"line_start":157},{"file":"references/mock-files.md","line_end":182,"line_start":182},{"file":"references/mock-files.md","line_end":324,"line_start":324},{"file":"references/mock-files.md","line_end":336,"line_start":336},{"file":"references/mock-files.md","line_end":340,"line_start":340},{"file":"references/quick-check.md","line_end":306,"line_start":306},{"file":"references/quick-check.md","line_end":306,"line_start":306},{"file":"references/quick-check.md","line_end":112,"line_start":112},{"file":"references/quick-check.md","line_end":113,"line_start":113},{"file":"references/standard-check.md","line_end":73,"line_start":73}]},{"factor":"external_commands","evidence":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":21,"line_start":21},{"file":"references/example-run.md","line_end":68,"line_start":59},{"file":"references/quick-check.md","line_end":298,"line_start":298},{"file":"references/quick-check.md","line_end":298,"line_start":298},{"file":"references/report-format.md","line_end":238,"line_start":238},{"file":"references/report-format.md","line_end":238,"line_start":234},{"file":"references/report-format.md","line_end":238,"line_start":238},{"file":"references/report-format.md","line_end":282,"line_start":281},{"file":"references/report-format.md","line_end":288,"line_start":282},{"file":"references/report-format.md","line_end":304,"line_start":302},{"file":"references/report-format.md","line_end":305,"line_start":304},{"file":"references/report-format.md","line_end":377,"line_start":370},{"file":"references/report-format.md","line_end":378,"line_start":377},{"file":"references/report-format.md","line_end":380,"line_start":378},{"file":"references/report-format.md","line_end":392,"line_start":391},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":134,"line_start":134},{"file":"SKILL.md","line_end":142,"line_start":142},{"file":"SKILL.md","line_end":154,"line_start":154},{"file":"SKILL.md","line_end":156,"line_start":156},{"file":"SKILL.md","line_end":157,"line_start":157},{"file":"SKILL.md","line_end":158,"line_start":158},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":193,"line_start":193},{"file":"SKILL.md","line_end":204,"line_start":204}]},{"factor":"network","evidence":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":15,"line_start":15}]},{"factor":"env_access","evidence":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":11,"line_start":11}]}],"critical_findings":[{"title":"SSH directory access","locations":[{"file":"references/quick-check.md","line_end":306,"line_start":306}],"description":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","review_kind":"security","source_category":"sensitive","source_severity":"critical"}],"high_findings":[{"title":"Dynamic code evaluation with eval()","locations":[{"file":"evals/evals.json","line_end":60,"line_start":60}],"description":"\"expected_output\": \"A report with multiple Critical security findings. The script contains shell inj","review_kind":"capability","source_category":"scripts","source_severity":"high"},{"title":"Dynamic code evaluation with eval()","locations":[{"file":"evals/evals.json","line_end":67,"line_start":67}],"description":"\"Security review flags eval() usage as Critical (arbitrary code execution)\",","review_kind":"capability","source_category":"scripts","source_severity":"high"},{"title":"Dynamic code evaluation with eval()","locations":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":27,"line_start":27}],"description":"result = eval(expression)","review_kind":"capability","source_category":"scripts","source_severity":"high"},{"title":"Python os.system","locations":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":21,"line_start":21}],"description":"os.system(f\"{user_command} {filepath}\")","review_kind":"capability","source_category":"external_commands","source_severity":"high"},{"title":"Generic API/secret keys","locations":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":11,"line_start":11}],"description":"API_KEY = \"sk-abc123-fake-key-for-testing-purposes\"","review_kind":"capability","source_category":"env_access","source_severity":"high"},{"title":"Hidden file in home directory","locations":[{"file":"README.md","line_end":46,"line_start":46}],"description":"cp -r skill-check ~/.claude/skills/","review_kind":"capability","source_category":"filesystem","source_severity":"high"},{"title":"Hidden file in home directory","locations":[{"file":"references/finding-the-skill.md","line_end":31,"line_start":31}],"description":"- `~/.claude/skills/` — personal skills","review_kind":"capability","source_category":"filesystem","source_severity":"high"},{"title":"Dynamic code evaluation with eval()","locations":[{"file":"references/quick-check.md","line_end":300,"line_start":300}],"description":"- Arbitrary code execution: `eval()`, `exec()`, `compile()` with dynamic input","review_kind":"capability","source_category":"scripts","source_severity":"high"},{"title":"Python subprocess.run","locations":[{"file":"references/quick-check.md","line_end":298,"line_start":298}],"description":"- Shell injection: `os.system(f\"...\")`, `subprocess.run(f\"...\", shell=True)` with","review_kind":"capability","source_category":"external_commands","source_severity":"high"},{"title":"Python os.system","locations":[{"file":"references/quick-check.md","line_end":298,"line_start":298}],"description":"- Shell injection: `os.system(f\"...\")`, `subprocess.run(f\"...\", shell=True)` with","review_kind":"capability","source_category":"external_commands","source_severity":"high"},{"title":"Hidden file in home directory","locations":[{"file":"references/quick-check.md","line_end":306,"line_start":306}],"description":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","review_kind":"capability","source_category":"filesystem","source_severity":"high"},{"title":"Hex-encoded characters","locations":[{"file":"references/quick-check.md","line_end":142,"line_start":142}],"description":"valid_headers = [b'\\x00\\x01\\x00\\x00', b'OTTO', b'true', b'typ1', b'wOFF', b'wOF2']","review_kind":"security","source_category":"obfuscation","source_severity":"high"},{"title":"Python subprocess.run","locations":[{"file":"references/report-format.md","line_end":238,"line_start":238}],"description":"- **SEC-I1**: `scripts/build_chart.py` uses `subprocess.run()` — appears properly","review_kind":"capability","source_category":"external_commands","source_severity":"high"},{"title":"Dynamic code evaluation with eval()","locations":[{"file":"references/standard-check.md","line_end":124,"line_start":124}],"description":"- Eval regression: 1 per existing eval (0 if none exist)","review_kind":"capability","source_category":"scripts","source_severity":"high"}],"medium_findings":[{"title":"Python file write/append","locations":[{"file":"evals/files/broken-skill/scripts/convert.py","line_end":15,"line_start":15}],"description":"with open(out_path, 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":16,"line_start":16}],"description":"with open(output_path, 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":32,"line_start":32}],"description":"with open(\"/etc/app-config.json\", 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Hidden file access","locations":[{"file":"README.md","line_end":46,"line_start":46}],"description":"cp -r skill-check ~/.claude/skills/","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/example-run.md","line_end":68,"line_start":59}],"description":"`python3 scripts/generate_chart.py --input <csv-path> --output <chart-path> --type <chart-type>`","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Hidden file access","locations":[{"file":"references/finding-the-skill.md","line_end":31,"line_start":31}],"description":"- `~/.claude/skills/` — personal skills","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"references/mock-files.md","line_end":98,"line_start":98}],"description":"with open(output_path, 'w', newline='') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"references/mock-files.md","line_end":135,"line_start":135}],"description":"with open(output_path, 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"references/mock-files.md","line_end":157,"line_start":157}],"description":"with open(output_path, 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"references/mock-files.md","line_end":182,"line_start":182}],"description":"with open(output_path, 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python file write/append","locations":[{"file":"references/mock-files.md","line_end":324,"line_start":324}],"description":"with open(output_path, 'w') as f:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python archive libraries","locations":[{"file":"references/mock-files.md","line_end":336,"line_start":336}],"description":"import zipfile","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python archive libraries","locations":[{"file":"references/mock-files.md","line_end":340,"line_start":340}],"description":"with zipfile.ZipFile(output_path, 'w') as zf:","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Hidden file access","locations":[{"file":"references/quick-check.md","line_end":306,"line_start":306}],"description":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python archive libraries","locations":[{"file":"references/quick-check.md","line_end":112,"line_start":112}],"description":"import zipfile","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Python archive libraries","locations":[{"file":"references/quick-check.md","line_end":113,"line_start":113}],"description":"assert zipfile.is_zipfile('<file>'), 'Not a valid ZIP-based document'","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":238,"line_start":234}],"description":"- **SEC-W1**: `scripts/fetch_data.py` line 42 — downloads from a URL constructed","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":238,"line_start":238}],"description":"- **SEC-I1**: `scripts/build_chart.py` uses `subprocess.run()` — appears properly","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":282,"line_start":281}],"description":"**What happened:** The script threw an unhandled `IndexError` on line 23:","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":288,"line_start":282}],"description":"`IndexError: list index out of range`","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":304,"line_start":302}],"description":"- **W-1**: `assets/old_logo.png` exists but is never referenced — orphaned file?","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":305,"line_start":304}],"description":"- **W-3**: `scripts/build_chart.py` has no comments — maintainability concern","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":377,"line_start":370}],"description":"1. Add argument validation to `scripts/build_chart.py` — currently crashes on missing input","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":378,"line_start":377}],"description":"4. Remove orphaned `assets/old_logo.png`","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":380,"line_start":378}],"description":"5. Add inline comments to `scripts/build_chart.py`","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"references/report-format.md","line_end":392,"line_start":391}],"description":"2. Remove orphaned `assets/old_logo.png`","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Temp directory access","locations":[{"file":"references/standard-check.md","line_end":73,"line_start":73}],"description":"python3 scripts/build_chart.py --input mock_data.csv --output /tmp/test_output.png 2>&1","review_kind":"capability","source_category":"filesystem","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":43,"line_start":43}],"description":"For a worked example of a Standard Check from start to finish, see `references/example-run.md`.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":49,"line_start":49}],"description":"- The `evals.json` format must match the skill-creator schema exactly (see","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":50,"line_start":50}],"description":"`references/eval-schema.md`). Don't invent a new format — compatibility with","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":55,"line_start":55}],"description":"See `references/mock-files.md` for the dependency list.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":69,"line_start":69}],"description":"`references/incomplete-skills.md` and reframe.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":74,"line_start":74}],"description":"- The frontmatter `name` field must match the parent directory name per the Agent","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":79,"line_start":79}],"description":"See `references/report-format.md` for collapsing rules.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":89,"line_start":89}],"description":"If the user gives a specific path, use it. If not, read `references/finding-the-skill.md`","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":98,"line_start":98}],"description":"| **Core**       | `SKILL.md` — the main instructions file                                |","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":99,"line_start":99}],"description":"| **Scripts**    | `scripts/` — executable code (Python, Bash, JS, etc.)                  |","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":100,"line_start":100}],"description":"| **References** | `references/` — documentation loaded into context as needed            |","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":101,"line_start":101}],"description":"| **Assets**     | `assets/` — templates, icons, fonts, images used in output             |","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":104,"line_start":104}],"description":"| **Evals**      | `evals/` — existing test cases (if any)                                |","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":132,"line_start":132}],"description":"integrity during testing — see `references/quick-check.md`.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":134,"line_start":134}],"description":"- **Evals**: Read `evals.json` if present. See `references/eval-schema.md` for the format.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":142,"line_start":142}],"description":"stub scripts), read `references/incomplete-skills.md` and adjust your approach — reframe","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":154,"line_start":154}],"description":"- **Quick:** `references/quick-check.md` — static integrity, asset validation, SKILL.md","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":156,"line_start":156}],"description":"22 best practice checks (`references/best-practices.md`)","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":157,"line_start":157}],"description":"- **Standard:** `references/standard-check.md` — everything in Quick, plus eval regression","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":158,"line_start":158}],"description":"(`references/eval-schema.md`), script execution with mock inputs (`references/mock-files.md`),","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":160,"line_start":160}],"description":"- **Deep:** `references/deep-check.md` — everything in Standard, plus edge case inputs,","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":193,"line_start":193}],"description":"Read `references/report-format.md` for the full template and collapsing rules. Key elements:","review_kind":"capability","source_category":"external_commands","source_severity":"medium"},{"title":"Ruby/shell backtick execution","locations":[{"file":"SKILL.md","line_end":204,"line_start":204}],"description":"`references/report-format.md` for which sections to skip at each depth level.","review_kind":"capability","source_category":"external_commands","source_severity":"medium"}],"low_findings":[{"title":"System reconnaissance","locations":[{"file":"CONTRIBUTING.md","line_end":59,"line_start":59}],"description":"SkillCheck follows the Agent Skills open standard. Avoid adding checks or behaviour","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"evals/evals.json","line_end":88,"line_start":88}],"description":"\"Script produces bullet-point output when given valid input\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"evals/files/healthy-skill/scripts/extract_key_points.py","line_end":16,"line_start":16}],"description":"print(f\"Error: File is not valid UTF-8 text: {filepath}\", file=sys.stderr)","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"Python HTTP libraries","locations":[{"file":"evals/files/insecure-skill/scripts/fetch_data.py","line_end":15,"line_start":15}],"description":"response = requests.get(url, verify=False)","review_kind":"capability","source_category":"network","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":150,"line_start":150}],"description":"- Keep file references one level deep from SKILL.md (per spec). Avoid deeply nested","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":190,"line_start":190}],"description":"- When NOT to use it (to avoid false positives)","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":255,"line_start":255}],"description":"**Severity:** Advisory. Skills with unexplained rigid rules tend to produce brittle outputs.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":298,"line_start":298}],"description":"- Examples treated as the only valid input rather than illustrations","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":340,"line_start":340}],"description":"- Redundant instructions (the same thing said multiple ways)","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":401,"line_start":401}],"description":"✓ BP-1:  Name format — \"csv-chart\", matches directory, valid format","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/deep-check.md","line_end":20,"line_start":20}],"description":"1. **Empty input** — A valid file of the correct type but with no meaningful content.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/deep-check.md","line_end":23,"line_start":23}],"description":"2. **Minimal input** — The absolute smallest valid input. One row, one field, one word.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/deep-check.md","line_end":59,"line_start":59}],"description":"5. Evaluate: did the output match what the skill promised?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":24,"line_start":24}],"description":"\"Output is a valid .pptx file\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":36,"line_start":36}],"description":"\"Output is a valid PNG image\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":73,"line_start":73}],"description":"1. **Schema check** — Is it valid JSON? Does it have `skill_name` and `evals`?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":80,"line_start":80}],"description":"Any validation failure is reported but doesn't prevent other valid evals from running.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":96,"line_start":96}],"description":"- \"Output is a valid .pptx file\" → Check file exists and is parseable","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":148,"line_start":148}],"description":"- Good: \"Output is a valid .pptx file with exactly 5 slides\"","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":153,"line_start":153}],"description":"- Bad: \"Output is a valid PDF and contains a table with 3 columns and a chart\"","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":171,"line_start":171}],"description":"\"Output is a valid .docx file\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":147,"line_start":147}],"description":"> - S3: Script syntax — generate_chart.py parses as valid Python","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":173,"line_start":172}],"description":"> - W-1: Step completability — Python available, script exists, paths valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":194,"line_start":194}],"description":"generate_chart.py parses as valid Python.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":279,"line_start":279}],"description":"Generated valid PNG chart (bar chart, 800x600).","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":288,"line_start":288}],"description":"Script produced a valid bar chart PNG with labeled axes.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":407,"line_start":406}],"description":"✓ BP-1:  Name format — valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/finding-the-skill.md","line_end":10,"line_start":10}],"description":"- Did the user mention a skill name or path earlier?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/finding-the-skill.md","line_end":11,"line_start":11}],"description":"- Did they just finish building a skill with skill-creator? If so, the path is likely","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/finding-the-skill.md","line_end":13,"line_start":13}],"description":"- Did they upload files that include a SKILL.md?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"Standard device file access","locations":[{"file":"references/mock-files.md","line_end":59,"line_start":59}],"description":"python3 -c \"import openpyxl\" 2>/dev/null && echo \"openpyxl: available\" || echo \"openpyxl: needs inst","review_kind":"capability","source_category":"filesystem","source_severity":"low"},{"title":"Standard device file access","locations":[{"file":"references/mock-files.md","line_end":60,"line_start":60}],"description":"python3 -c \"import docx\" 2>/dev/null && echo \"python-docx: available\" || echo \"python-docx: needs in","review_kind":"capability","source_category":"filesystem","source_severity":"low"},{"title":"Standard device file access","locations":[{"file":"references/mock-files.md","line_end":61,"line_start":61}],"description":"python3 -c \"import pptx\" 2>/dev/null && echo \"python-pptx: available\" || echo \"python-pptx: needs in","review_kind":"capability","source_category":"filesystem","source_severity":"low"},{"title":"Standard device file access","locations":[{"file":"references/mock-files.md","line_end":62,"line_start":62}],"description":"python3 -c \"import fpdf\" 2>/dev/null && echo \"fpdf2: available\" || echo \"fpdf2: needs install\"","review_kind":"capability","source_category":"filesystem","source_severity":"low"},{"title":"Standard device file access","locations":[{"file":"references/mock-files.md","line_end":63,"line_start":63}],"description":"python3 -c \"import PIL\" 2>/dev/null && echo \"Pillow: available\" || echo \"Pillow: needs install\"","review_kind":"capability","source_category":"filesystem","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":305,"line_start":305}],"description":"# Draw a grid and label","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":351,"line_start":350}],"description":"For any code file type (.py, .js, .ts, .sh, .sql, etc.), generate syntactically valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":352,"line_start":352}],"description":"small valid Python module. If it processes SQL, write a few CREATE TABLE / SELECT statements.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":362,"line_start":362}],"description":"3. If binary and no library, create the simplest valid file of that type you can","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":57,"line_start":57}],"description":"files referenced by the skill), verify it's a valid file of its claimed type:","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":71,"line_start":71}],"description":"For SVG, check it's valid XML with an `<svg>` root element:","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":78,"line_start":78}],"description":"print('PASS: valid SVG')","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":108,"line_start":108}],"description":"If the required library isn't available, fall back to checking the file is a valid ZIP","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":113,"line_start":113}],"description":"assert zipfile.is_zipfile('<file>'), 'Not a valid ZIP-based document'","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":114,"line_start":114}],"description":"print('PASS: valid ZIP container')","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":128,"line_start":128}],"description":"print('PASS: valid PDF structure')","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/report-format.md","line_end":211,"line_start":211}],"description":"- **S2** Script syntax: scripts/build_chart.py valid Python ✓","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/report-format.md","line_end":213,"line_start":213}],"description":"- **IO1** Happy path: CSV → PPTX conversion produced valid 5-slide deck ✓","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/report-format.md","line_end":351,"line_start":350}],"description":"✓ BP-1:  Name format — valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":29,"line_start":29}],"description":"and input file existence. Report any validation errors but continue with valid evals.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":40,"line_start":40}],"description":"- Descriptive assertions (\"output should be a valid PDF\") — evaluate by inspection","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":68,"line_start":68}],"description":"2. **Generate minimal mock input** — Create the simplest valid input the script needs.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":80,"line_start":80}],"description":"- Output files are non-empty and parseable (e.g., valid PNG, valid JSON)","review_kind":"security","source_category":"blocker","source_severity":"low"}],"dangerous_patterns":[{"title":"System reconnaissance","locations":[{"file":"CONTRIBUTING.md","line_end":59,"line_start":59}],"description":"SkillCheck follows the Agent Skills open standard. Avoid adding checks or behaviour","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"evals/evals.json","line_end":88,"line_start":88}],"description":"\"Script produces bullet-point output when given valid input\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"evals/files/healthy-skill/scripts/extract_key_points.py","line_end":16,"line_start":16}],"description":"print(f\"Error: File is not valid UTF-8 text: {filepath}\", file=sys.stderr)","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":150,"line_start":150}],"description":"- Keep file references one level deep from SKILL.md (per spec). Avoid deeply nested","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":190,"line_start":190}],"description":"- When NOT to use it (to avoid false positives)","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":255,"line_start":255}],"description":"**Severity:** Advisory. Skills with unexplained rigid rules tend to produce brittle outputs.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":298,"line_start":298}],"description":"- Examples treated as the only valid input rather than illustrations","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":340,"line_start":340}],"description":"- Redundant instructions (the same thing said multiple ways)","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/best-practices.md","line_end":401,"line_start":401}],"description":"✓ BP-1:  Name format — \"csv-chart\", matches directory, valid format","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/deep-check.md","line_end":20,"line_start":20}],"description":"1. **Empty input** — A valid file of the correct type but with no meaningful content.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/deep-check.md","line_end":23,"line_start":23}],"description":"2. **Minimal input** — The absolute smallest valid input. One row, one field, one word.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/deep-check.md","line_end":59,"line_start":59}],"description":"5. Evaluate: did the output match what the skill promised?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":24,"line_start":24}],"description":"\"Output is a valid .pptx file\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":36,"line_start":36}],"description":"\"Output is a valid PNG image\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":73,"line_start":73}],"description":"1. **Schema check** — Is it valid JSON? Does it have `skill_name` and `evals`?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":80,"line_start":80}],"description":"Any validation failure is reported but doesn't prevent other valid evals from running.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":96,"line_start":96}],"description":"- \"Output is a valid .pptx file\" → Check file exists and is parseable","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":148,"line_start":148}],"description":"- Good: \"Output is a valid .pptx file with exactly 5 slides\"","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":153,"line_start":153}],"description":"- Bad: \"Output is a valid PDF and contains a table with 3 columns and a chart\"","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/eval-schema.md","line_end":171,"line_start":171}],"description":"\"Output is a valid .docx file\",","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":147,"line_start":147}],"description":"> - S3: Script syntax — generate_chart.py parses as valid Python","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":173,"line_start":172}],"description":"> - W-1: Step completability — Python available, script exists, paths valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":194,"line_start":194}],"description":"generate_chart.py parses as valid Python.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":279,"line_start":279}],"description":"Generated valid PNG chart (bar chart, 800x600).","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":288,"line_start":288}],"description":"Script produced a valid bar chart PNG with labeled axes.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/example-run.md","line_end":407,"line_start":406}],"description":"✓ BP-1:  Name format — valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/finding-the-skill.md","line_end":10,"line_start":10}],"description":"- Did the user mention a skill name or path earlier?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/finding-the-skill.md","line_end":11,"line_start":11}],"description":"- Did they just finish building a skill with skill-creator? If so, the path is likely","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/finding-the-skill.md","line_end":13,"line_start":13}],"description":"- Did they upload files that include a SKILL.md?","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":305,"line_start":305}],"description":"# Draw a grid and label","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":351,"line_start":350}],"description":"For any code file type (.py, .js, .ts, .sh, .sql, etc.), generate syntactically valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":352,"line_start":352}],"description":"small valid Python module. If it processes SQL, write a few CREATE TABLE / SELECT statements.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/mock-files.md","line_end":362,"line_start":362}],"description":"3. If binary and no library, create the simplest valid file of that type you can","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"SSH directory access","locations":[{"file":"references/quick-check.md","line_end":306,"line_start":306}],"description":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","review_kind":"security","source_category":"sensitive","source_severity":"critical"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":57,"line_start":57}],"description":"files referenced by the skill), verify it's a valid file of its claimed type:","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":71,"line_start":71}],"description":"For SVG, check it's valid XML with an `<svg>` root element:","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":78,"line_start":78}],"description":"print('PASS: valid SVG')","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":108,"line_start":108}],"description":"If the required library isn't available, fall back to checking the file is a valid ZIP","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":113,"line_start":113}],"description":"assert zipfile.is_zipfile('<file>'), 'Not a valid ZIP-based document'","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":114,"line_start":114}],"description":"print('PASS: valid ZIP container')","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/quick-check.md","line_end":128,"line_start":128}],"description":"print('PASS: valid PDF structure')","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/report-format.md","line_end":211,"line_start":211}],"description":"- **S2** Script syntax: scripts/build_chart.py valid Python ✓","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/report-format.md","line_end":213,"line_start":213}],"description":"- **IO1** Happy path: CSV → PPTX conversion produced valid 5-slide deck ✓","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/report-format.md","line_end":351,"line_start":350}],"description":"✓ BP-1:  Name format — valid","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":29,"line_start":29}],"description":"and input file existence. Report any validation errors but continue with valid evals.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":40,"line_start":40}],"description":"- Descriptive assertions (\"output should be a valid PDF\") — evaluate by inspection","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":68,"line_start":68}],"description":"2. **Generate minimal mock input** — Create the simplest valid input the script needs.","review_kind":"security","source_category":"blocker","source_severity":"low"},{"title":"System reconnaissance","locations":[{"file":"references/standard-check.md","line_end":80,"line_start":80}],"description":"- Output files are non-empty and parseable (e.g., valid PNG, valid JSON)","review_kind":"security","source_category":"blocker","source_severity":"low"}],"files_scanned":22,"total_lines":3439,"audit_model":"claude","audited_at":"2026-07-09T04:00:27.204+00:00","created_at":"2026-07-09T06:44:13.566927+00:00","static_findings":[{"id":"blocker:CONTRIBUTING.md:59:system-reconnaissance","file":"CONTRIBUTING.md","pattern":"System reconnaissance","snippet":"SkillCheck follows the Agent Skills open standard. Avoid adding checks or behaviour","category":"blocker","line_end":59,"severity":"low","line_start":59},{"id":"scripts:evals/evals.json:60:dynamic-code-evaluation-with-eval","file":"evals/evals.json","pattern":"Dynamic code evaluation with eval()","snippet":"\"expected_output\": \"A report with multiple Critical security findings. The script contains shell inj","category":"scripts","line_end":60,"severity":"high","line_start":60},{"id":"scripts:evals/evals.json:67:dynamic-code-evaluation-with-eval","file":"evals/evals.json","pattern":"Dynamic code evaluation with eval()","snippet":"\"Security review flags eval() usage as Critical (arbitrary code execution)\",","category":"scripts","line_end":67,"severity":"high","line_start":67},{"id":"blocker:evals/evals.json:88:system-reconnaissance","file":"evals/evals.json","pattern":"System reconnaissance","snippet":"\"Script produces bullet-point output when given valid input\",","category":"blocker","line_end":88,"severity":"low","line_start":88},{"id":"filesystem:evals/files/broken-skill/scripts/convert.py:15:python-file-write-append","file":"evals/files/broken-skill/scripts/convert.py","pattern":"Python file write/append","snippet":"with open(out_path, 'w') as f:","category":"filesystem","line_end":15,"severity":"medium","line_start":15},{"id":"blocker:evals/files/healthy-skill/scripts/extract_key_points.py:16:system-reconnaissance","file":"evals/files/healthy-skill/scripts/extract_key_points.py","pattern":"System reconnaissance","snippet":"print(f\"Error: File is not valid UTF-8 text: {filepath}\", file=sys.stderr)","category":"blocker","line_end":16,"severity":"low","line_start":16},{"id":"scripts:evals/files/insecure-skill/scripts/fetch_data.py:27:dynamic-code-evaluation-with-eval","file":"evals/files/insecure-skill/scripts/fetch_data.py","pattern":"Dynamic code evaluation with eval()","snippet":"result = eval(expression)","category":"scripts","line_end":27,"severity":"high","line_start":27},{"id":"external_commands:evals/files/insecure-skill/scripts/fetch_data.py:21:python-os-system","file":"evals/files/insecure-skill/scripts/fetch_data.py","pattern":"Python os.system","snippet":"os.system(f\"{user_command} {filepath}\")","category":"external_commands","line_end":21,"severity":"high","line_start":21},{"id":"network:evals/files/insecure-skill/scripts/fetch_data.py:15:python-http-libraries","file":"evals/files/insecure-skill/scripts/fetch_data.py","pattern":"Python HTTP libraries","snippet":"response = requests.get(url, verify=False)","category":"network","line_end":15,"severity":"low","line_start":15},{"id":"filesystem:evals/files/insecure-skill/scripts/fetch_data.py:16:python-file-write-append","file":"evals/files/insecure-skill/scripts/fetch_data.py","pattern":"Python file write/append","snippet":"with open(output_path, 'w') as f:","category":"filesystem","line_end":16,"severity":"medium","line_start":16},{"id":"filesystem:evals/files/insecure-skill/scripts/fetch_data.py:32:python-file-write-append","file":"evals/files/insecure-skill/scripts/fetch_data.py","pattern":"Python file write/append","snippet":"with open(\"/etc/app-config.json\", 'w') as f:","category":"filesystem","line_end":32,"severity":"medium","line_start":32},{"id":"env_access:evals/files/insecure-skill/scripts/fetch_data.py:11:generic-api-secret-keys","file":"evals/files/insecure-skill/scripts/fetch_data.py","pattern":"Generic API/secret keys","snippet":"API_KEY = \"sk-abc123-fake-key-for-testing-purposes\"","category":"env_access","line_end":11,"severity":"high","line_start":11},{"id":"filesystem:README.md:46:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"cp -r skill-check ~/.claude/skills/","category":"filesystem","line_end":46,"severity":"high","line_start":46},{"id":"filesystem:README.md:46:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"cp -r skill-check ~/.claude/skills/","category":"filesystem","line_end":46,"severity":"medium","line_start":46},{"id":"blocker:references/best-practices.md:150:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"- Keep file references one level deep from SKILL.md (per spec). Avoid deeply nested","category":"blocker","line_end":150,"severity":"low","line_start":150},{"id":"blocker:references/best-practices.md:190:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"- When NOT to use it (to avoid false positives)","category":"blocker","line_end":190,"severity":"low","line_start":190},{"id":"blocker:references/best-practices.md:255:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"**Severity:** Advisory. Skills with unexplained rigid rules tend to produce brittle outputs.","category":"blocker","line_end":255,"severity":"low","line_start":255},{"id":"blocker:references/best-practices.md:298:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"- Examples treated as the only valid input rather than illustrations","category":"blocker","line_end":298,"severity":"low","line_start":298},{"id":"blocker:references/best-practices.md:340:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"- Redundant instructions (the same thing said multiple ways)","category":"blocker","line_end":340,"severity":"low","line_start":340},{"id":"blocker:references/best-practices.md:401:system-reconnaissance","file":"references/best-practices.md","pattern":"System reconnaissance","snippet":"✓ BP-1:  Name format — \"csv-chart\", matches directory, valid format","category":"blocker","line_end":401,"severity":"low","line_start":401},{"id":"blocker:references/deep-check.md:20:system-reconnaissance","file":"references/deep-check.md","pattern":"System reconnaissance","snippet":"1. **Empty input** — A valid file of the correct type but with no meaningful content.","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:references/deep-check.md:23:system-reconnaissance","file":"references/deep-check.md","pattern":"System reconnaissance","snippet":"2. **Minimal input** — The absolute smallest valid input. One row, one field, one word.","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"blocker:references/deep-check.md:59:system-reconnaissance","file":"references/deep-check.md","pattern":"System reconnaissance","snippet":"5. Evaluate: did the output match what the skill promised?","category":"blocker","line_end":59,"severity":"low","line_start":59},{"id":"blocker:references/eval-schema.md:24:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"\"Output is a valid .pptx file\",","category":"blocker","line_end":24,"severity":"low","line_start":24},{"id":"blocker:references/eval-schema.md:36:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"\"Output is a valid PNG image\",","category":"blocker","line_end":36,"severity":"low","line_start":36},{"id":"blocker:references/eval-schema.md:73:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"1. **Schema check** — Is it valid JSON? Does it have `skill_name` and `evals`?","category":"blocker","line_end":73,"severity":"low","line_start":73},{"id":"blocker:references/eval-schema.md:80:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"Any validation failure is reported but doesn't prevent other valid evals from running.","category":"blocker","line_end":80,"severity":"low","line_start":80},{"id":"blocker:references/eval-schema.md:96:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"- \"Output is a valid .pptx file\" → Check file exists and is parseable","category":"blocker","line_end":96,"severity":"low","line_start":96},{"id":"blocker:references/eval-schema.md:148:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"- Good: \"Output is a valid .pptx file with exactly 5 slides\"","category":"blocker","line_end":148,"severity":"low","line_start":148},{"id":"blocker:references/eval-schema.md:153:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"- Bad: \"Output is a valid PDF and contains a table with 3 columns and a chart\"","category":"blocker","line_end":153,"severity":"low","line_start":153},{"id":"blocker:references/eval-schema.md:171:system-reconnaissance","file":"references/eval-schema.md","pattern":"System reconnaissance","snippet":"\"Output is a valid .docx file\",","category":"blocker","line_end":171,"severity":"low","line_start":171},{"id":"external_commands:references/example-run.md:59:ruby-shell-backtick-execution","file":"references/example-run.md","pattern":"Ruby/shell backtick execution","snippet":"`python3 scripts/generate_chart.py --input <csv-path> --output <chart-path> --type <chart-type>`","category":"external_commands","line_end":68,"severity":"medium","line_start":59},{"id":"blocker:references/example-run.md:147:system-reconnaissance","file":"references/example-run.md","pattern":"System reconnaissance","snippet":"> - S3: Script syntax — generate_chart.py parses as valid Python","category":"blocker","line_end":147,"severity":"low","line_start":147},{"id":"blocker:references/example-run.md:172:system-reconnaissance","file":"references/example-run.md","pattern":"System reconnaissance","snippet":"> - W-1: Step completability — Python available, script exists, paths valid","category":"blocker","line_end":173,"severity":"low","line_start":172},{"id":"blocker:references/example-run.md:194:system-reconnaissance","file":"references/example-run.md","pattern":"System reconnaissance","snippet":"generate_chart.py parses as valid Python.","category":"blocker","line_end":194,"severity":"low","line_start":194},{"id":"blocker:references/example-run.md:279:system-reconnaissance","file":"references/example-run.md","pattern":"System reconnaissance","snippet":"Generated valid PNG chart (bar chart, 800x600).","category":"blocker","line_end":279,"severity":"low","line_start":279},{"id":"blocker:references/example-run.md:288:system-reconnaissance","file":"references/example-run.md","pattern":"System reconnaissance","snippet":"Script produced a valid bar chart PNG with labeled axes.","category":"blocker","line_end":288,"severity":"low","line_start":288},{"id":"blocker:references/example-run.md:406:system-reconnaissance","file":"references/example-run.md","pattern":"System reconnaissance","snippet":"✓ BP-1:  Name format — valid","category":"blocker","line_end":407,"severity":"low","line_start":406},{"id":"filesystem:references/finding-the-skill.md:31:hidden-file-in-home-directory","file":"references/finding-the-skill.md","pattern":"Hidden file in home directory","snippet":"- `~/.claude/skills/` — personal skills","category":"filesystem","line_end":31,"severity":"high","line_start":31},{"id":"filesystem:references/finding-the-skill.md:31:hidden-file-access","file":"references/finding-the-skill.md","pattern":"Hidden file access","snippet":"- `~/.claude/skills/` — personal skills","category":"filesystem","line_end":31,"severity":"medium","line_start":31},{"id":"blocker:references/finding-the-skill.md:10:system-reconnaissance","file":"references/finding-the-skill.md","pattern":"System reconnaissance","snippet":"- Did the user mention a skill name or path earlier?","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:references/finding-the-skill.md:11:system-reconnaissance","file":"references/finding-the-skill.md","pattern":"System reconnaissance","snippet":"- Did they just finish building a skill with skill-creator? If so, the path is likely","category":"blocker","line_end":11,"severity":"low","line_start":11},{"id":"blocker:references/finding-the-skill.md:13:system-reconnaissance","file":"references/finding-the-skill.md","pattern":"System reconnaissance","snippet":"- Did they upload files that include a SKILL.md?","category":"blocker","line_end":13,"severity":"low","line_start":13},{"id":"filesystem:references/mock-files.md:59:standard-device-file-access","file":"references/mock-files.md","pattern":"Standard device file access","snippet":"python3 -c \"import openpyxl\" 2>/dev/null && echo \"openpyxl: available\" || echo \"openpyxl: needs inst","category":"filesystem","line_end":59,"severity":"low","line_start":59},{"id":"filesystem:references/mock-files.md:60:standard-device-file-access","file":"references/mock-files.md","pattern":"Standard device file access","snippet":"python3 -c \"import docx\" 2>/dev/null && echo \"python-docx: available\" || echo \"python-docx: needs in","category":"filesystem","line_end":60,"severity":"low","line_start":60},{"id":"filesystem:references/mock-files.md:61:standard-device-file-access","file":"references/mock-files.md","pattern":"Standard device file access","snippet":"python3 -c \"import pptx\" 2>/dev/null && echo \"python-pptx: available\" || echo \"python-pptx: needs in","category":"filesystem","line_end":61,"severity":"low","line_start":61},{"id":"filesystem:references/mock-files.md:62:standard-device-file-access","file":"references/mock-files.md","pattern":"Standard device file access","snippet":"python3 -c \"import fpdf\" 2>/dev/null && echo \"fpdf2: available\" || echo \"fpdf2: needs install\"","category":"filesystem","line_end":62,"severity":"low","line_start":62},{"id":"filesystem:references/mock-files.md:63:standard-device-file-access","file":"references/mock-files.md","pattern":"Standard device file access","snippet":"python3 -c \"import PIL\" 2>/dev/null && echo \"Pillow: available\" || echo \"Pillow: needs install\"","category":"filesystem","line_end":63,"severity":"low","line_start":63},{"id":"filesystem:references/mock-files.md:98:python-file-write-append","file":"references/mock-files.md","pattern":"Python file write/append","snippet":"with open(output_path, 'w', newline='') as f:","category":"filesystem","line_end":98,"severity":"medium","line_start":98},{"id":"filesystem:references/mock-files.md:135:python-file-write-append","file":"references/mock-files.md","pattern":"Python file write/append","snippet":"with open(output_path, 'w') as f:","category":"filesystem","line_end":135,"severity":"medium","line_start":135},{"id":"filesystem:references/mock-files.md:157:python-file-write-append","file":"references/mock-files.md","pattern":"Python file write/append","snippet":"with open(output_path, 'w') as f:","category":"filesystem","line_end":157,"severity":"medium","line_start":157},{"id":"filesystem:references/mock-files.md:182:python-file-write-append","file":"references/mock-files.md","pattern":"Python file write/append","snippet":"with open(output_path, 'w') as f:","category":"filesystem","line_end":182,"severity":"medium","line_start":182},{"id":"filesystem:references/mock-files.md:324:python-file-write-append","file":"references/mock-files.md","pattern":"Python file write/append","snippet":"with open(output_path, 'w') as f:","category":"filesystem","line_end":324,"severity":"medium","line_start":324},{"id":"filesystem:references/mock-files.md:336:python-archive-libraries","file":"references/mock-files.md","pattern":"Python archive libraries","snippet":"import zipfile","category":"filesystem","line_end":336,"severity":"medium","line_start":336},{"id":"filesystem:references/mock-files.md:340:python-archive-libraries","file":"references/mock-files.md","pattern":"Python archive libraries","snippet":"with zipfile.ZipFile(output_path, 'w') as zf:","category":"filesystem","line_end":340,"severity":"medium","line_start":340},{"id":"blocker:references/mock-files.md:305:system-reconnaissance","file":"references/mock-files.md","pattern":"System reconnaissance","snippet":"# Draw a grid and label","category":"blocker","line_end":305,"severity":"low","line_start":305},{"id":"blocker:references/mock-files.md:350:system-reconnaissance","file":"references/mock-files.md","pattern":"System reconnaissance","snippet":"For any code file type (.py, .js, .ts, .sh, .sql, etc.), generate syntactically valid","category":"blocker","line_end":351,"severity":"low","line_start":350},{"id":"blocker:references/mock-files.md:352:system-reconnaissance","file":"references/mock-files.md","pattern":"System reconnaissance","snippet":"small valid Python module. If it processes SQL, write a few CREATE TABLE / SELECT statements.","category":"blocker","line_end":352,"severity":"low","line_start":352},{"id":"blocker:references/mock-files.md:362:system-reconnaissance","file":"references/mock-files.md","pattern":"System reconnaissance","snippet":"3. If binary and no library, create the simplest valid file of that type you can","category":"blocker","line_end":362,"severity":"low","line_start":362},{"id":"scripts:references/quick-check.md:300:dynamic-code-evaluation-with-eval","file":"references/quick-check.md","pattern":"Dynamic code evaluation with eval()","snippet":"- Arbitrary code execution: `eval()`, `exec()`, `compile()` with dynamic input","category":"scripts","line_end":300,"severity":"high","line_start":300},{"id":"external_commands:references/quick-check.md:298:python-subprocess-run","file":"references/quick-check.md","pattern":"Python subprocess.run","snippet":"- Shell injection: `os.system(f\"...\")`, `subprocess.run(f\"...\", shell=True)` with","category":"external_commands","line_end":298,"severity":"high","line_start":298},{"id":"external_commands:references/quick-check.md:298:python-os-system","file":"references/quick-check.md","pattern":"Python os.system","snippet":"- Shell injection: `os.system(f\"...\")`, `subprocess.run(f\"...\", shell=True)` with","category":"external_commands","line_end":298,"severity":"high","line_start":298},{"id":"filesystem:references/quick-check.md:306:hidden-file-in-home-directory","file":"references/quick-check.md","pattern":"Hidden file in home directory","snippet":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","category":"filesystem","line_end":306,"severity":"high","line_start":306},{"id":"filesystem:references/quick-check.md:306:hidden-file-access","file":"references/quick-check.md","pattern":"Hidden file access","snippet":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","category":"filesystem","line_end":306,"severity":"medium","line_start":306},{"id":"filesystem:references/quick-check.md:112:python-archive-libraries","file":"references/quick-check.md","pattern":"Python archive libraries","snippet":"import zipfile","category":"filesystem","line_end":112,"severity":"medium","line_start":112},{"id":"filesystem:references/quick-check.md:113:python-archive-libraries","file":"references/quick-check.md","pattern":"Python archive libraries","snippet":"assert zipfile.is_zipfile('<file>'), 'Not a valid ZIP-based document'","category":"filesystem","line_end":113,"severity":"medium","line_start":113},{"id":"obfuscation:references/quick-check.md:142:hex-encoded-characters","file":"references/quick-check.md","pattern":"Hex-encoded characters","snippet":"valid_headers = [b'\\x00\\x01\\x00\\x00', b'OTTO', b'true', b'typ1', b'wOFF', b'wOF2']","category":"obfuscation","line_end":142,"severity":"high","line_start":142},{"id":"sensitive:references/quick-check.md:306:ssh-directory-access","file":"references/quick-check.md","pattern":"SSH directory access","snippet":"- Writing to sensitive paths: `/etc/`, `/usr/`, `~/.ssh/`, `~/.config/`, system dirs","category":"sensitive","line_end":306,"severity":"critical","line_start":306},{"id":"blocker:references/quick-check.md:57:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"files referenced by the skill), verify it's a valid file of its claimed type:","category":"blocker","line_end":57,"severity":"low","line_start":57},{"id":"blocker:references/quick-check.md:71:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"For SVG, check it's valid XML with an `<svg>` root element:","category":"blocker","line_end":71,"severity":"low","line_start":71},{"id":"blocker:references/quick-check.md:78:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"print('PASS: valid SVG')","category":"blocker","line_end":78,"severity":"low","line_start":78},{"id":"blocker:references/quick-check.md:108:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"If the required library isn't available, fall back to checking the file is a valid ZIP","category":"blocker","line_end":108,"severity":"low","line_start":108},{"id":"blocker:references/quick-check.md:113:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"assert zipfile.is_zipfile('<file>'), 'Not a valid ZIP-based document'","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/quick-check.md:114:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"print('PASS: valid ZIP container')","category":"blocker","line_end":114,"severity":"low","line_start":114},{"id":"blocker:references/quick-check.md:128:system-reconnaissance","file":"references/quick-check.md","pattern":"System reconnaissance","snippet":"print('PASS: valid PDF structure')","category":"blocker","line_end":128,"severity":"low","line_start":128},{"id":"external_commands:references/report-format.md:238:python-subprocess-run","file":"references/report-format.md","pattern":"Python subprocess.run","snippet":"- **SEC-I1**: `scripts/build_chart.py` uses `subprocess.run()` — appears properly","category":"external_commands","line_end":238,"severity":"high","line_start":238},{"id":"external_commands:references/report-format.md:234:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"- **SEC-W1**: `scripts/fetch_data.py` line 42 — downloads from a URL constructed","category":"external_commands","line_end":238,"severity":"medium","line_start":234},{"id":"external_commands:references/report-format.md:238:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"- **SEC-I1**: `scripts/build_chart.py` uses `subprocess.run()` — appears properly","category":"external_commands","line_end":238,"severity":"medium","line_start":238},{"id":"external_commands:references/report-format.md:281:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"**What happened:** The script threw an unhandled `IndexError` on line 23:","category":"external_commands","line_end":282,"severity":"medium","line_start":281},{"id":"external_commands:references/report-format.md:282:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"`IndexError: list index out of range`","category":"external_commands","line_end":288,"severity":"medium","line_start":282},{"id":"external_commands:references/report-format.md:302:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"- **W-1**: `assets/old_logo.png` exists but is never referenced — orphaned file?","category":"external_commands","line_end":304,"severity":"medium","line_start":302},{"id":"external_commands:references/report-format.md:304:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"- **W-3**: `scripts/build_chart.py` has no comments — maintainability concern","category":"external_commands","line_end":305,"severity":"medium","line_start":304},{"id":"external_commands:references/report-format.md:370:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"1. Add argument validation to `scripts/build_chart.py` — currently crashes on missing input","category":"external_commands","line_end":377,"severity":"medium","line_start":370},{"id":"external_commands:references/report-format.md:377:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"4. Remove orphaned `assets/old_logo.png`","category":"external_commands","line_end":378,"severity":"medium","line_start":377},{"id":"external_commands:references/report-format.md:378:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"5. Add inline comments to `scripts/build_chart.py`","category":"external_commands","line_end":380,"severity":"medium","line_start":378},{"id":"external_commands:references/report-format.md:391:ruby-shell-backtick-execution","file":"references/report-format.md","pattern":"Ruby/shell backtick execution","snippet":"2. Remove orphaned `assets/old_logo.png`","category":"external_commands","line_end":392,"severity":"medium","line_start":391},{"id":"blocker:references/report-format.md:211:system-reconnaissance","file":"references/report-format.md","pattern":"System reconnaissance","snippet":"- **S2** Script syntax: scripts/build_chart.py valid Python ✓","category":"blocker","line_end":211,"severity":"low","line_start":211},{"id":"blocker:references/report-format.md:213:system-reconnaissance","file":"references/report-format.md","pattern":"System reconnaissance","snippet":"- **IO1** Happy path: CSV → PPTX conversion produced valid 5-slide deck ✓","category":"blocker","line_end":213,"severity":"low","line_start":213},{"id":"blocker:references/report-format.md:350:system-reconnaissance","file":"references/report-format.md","pattern":"System reconnaissance","snippet":"✓ BP-1:  Name format — valid","category":"blocker","line_end":351,"severity":"low","line_start":350},{"id":"scripts:references/standard-check.md:124:dynamic-code-evaluation-with-eval","file":"references/standard-check.md","pattern":"Dynamic code evaluation with eval()","snippet":"- Eval regression: 1 per existing eval (0 if none exist)","category":"scripts","line_end":124,"severity":"high","line_start":124},{"id":"filesystem:references/standard-check.md:73:temp-directory-access","file":"references/standard-check.md","pattern":"Temp directory access","snippet":"python3 scripts/build_chart.py --input mock_data.csv --output /tmp/test_output.png 2>&1","category":"filesystem","line_end":73,"severity":"medium","line_start":73},{"id":"blocker:references/standard-check.md:29:system-reconnaissance","file":"references/standard-check.md","pattern":"System reconnaissance","snippet":"and input file existence. Report any validation errors but continue with valid evals.","category":"blocker","line_end":29,"severity":"low","line_start":29},{"id":"blocker:references/standard-check.md:40:system-reconnaissance","file":"references/standard-check.md","pattern":"System reconnaissance","snippet":"- Descriptive assertions (\"output should be a valid PDF\") — evaluate by inspection","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"blocker:references/standard-check.md:68:system-reconnaissance","file":"references/standard-check.md","pattern":"System reconnaissance","snippet":"2. **Generate minimal mock input** — Create the simplest valid input the script needs.","category":"blocker","line_end":68,"severity":"low","line_start":68},{"id":"blocker:references/standard-check.md:80:system-reconnaissance","file":"references/standard-check.md","pattern":"System reconnaissance","snippet":"- Output files are non-empty and parseable (e.g., valid PNG, valid JSON)","category":"blocker","line_end":80,"severity":"low","line_start":80},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For a worked example of a Standard Check from start to finish, see `references/example-run.md`.","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The `evals.json` format must match the skill-creator schema exactly (see","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`references/eval-schema.md`). Don't invent a new format — compatibility with","category":"external_commands","line_end":50,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `references/mock-files.md` for the dependency list.","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`references/incomplete-skills.md` and reframe.","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- The frontmatter `name` field must match the parent directory name per the Agent","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `references/report-format.md` for collapsing rules.","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the user gives a specific path, use it. If not, read `references/finding-the-skill.md`","category":"external_commands","line_end":89,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Core**       | `SKILL.md` — the main instructions file                                |","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Scripts**    | `scripts/` — executable code (Python, Bash, JS, etc.)                  |","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **References** | `references/` — documentation loaded into context as needed            |","category":"external_commands","line_end":100,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Assets**     | `assets/` — templates, icons, fonts, images used in output             |","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Evals**      | `evals/` — existing test cases (if any)                                |","category":"external_commands","line_end":104,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"integrity during testing — see `references/quick-check.md`.","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Evals**: Read `evals.json` if present. See `references/eval-schema.md` for the format.","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"stub scripts), read `references/incomplete-skills.md` and adjust your approach — reframe","category":"external_commands","line_end":142,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Quick:** `references/quick-check.md` — static integrity, asset validation, SKILL.md","category":"external_commands","line_end":154,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"22 best practice checks (`references/best-practices.md`)","category":"external_commands","line_end":156,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Standard:** `references/standard-check.md` — everything in Quick, plus eval regression","category":"external_commands","line_end":157,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`references/eval-schema.md`), script execution with mock inputs (`references/mock-files.md`),","category":"external_commands","line_end":158,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Deep:** `references/deep-check.md` — everything in Standard, plus edge case inputs,","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read `references/report-format.md` for the full template and collapsing rules. Key elements:","category":"external_commands","line_end":193,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:204:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`references/report-format.md` for which sections to skip at each depth level.","category":"external_commands","line_end":204,"severity":"medium","line_start":204}],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"analysis_status=failed"},"trust":{"publicState":"public","auditState":"failed","auditCurrentness":null,"confirmedRiskLevel":null,"confirmedFindingCount":49,"capabilityReviewCount":69,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"blocked","manualInstallPolicy":"allowed_with_warning","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}