{"data":{"skill":{"slug":"jeffallan-laravel-specialist","name":"laravel-specialist","icon":"📦","repo":"https://github.com/jeffallan/claude-skills/tree/main/skills/laravel-specialist/","status":"approved","author":"jeffallan","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"4cb4aa8a-1fc1-4478-ab14-2e5e318d5fe5","skill_id":"98a4711c-697e-4ed3-b3c6-5e65d04ff40b","version":1,"content_hash":"b35800857f1b318d54447dce7505d05b","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"All static scanner findings are false positives. The skill contains legitimate Laravel PHP code examples with no security risks. Scanner misidentified PHP syntax as shell commands, Laravel methods as weak crypto, and standard config patterns as credential access.","remediation":[],"risk_factor_evidence":[],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"External Commands Detection - False Positive","locations":[{"file":"references/eloquent.md","line_end":340,"line_start":5},{"file":"references/livewire.md","line_end":512,"line_start":5},{"file":"references/queues.md","line_end":410,"line_start":5},{"file":"references/routing.md","line_end":362,"line_start":5},{"file":"references/testing.md","line_end":509,"line_start":5},{"file":"SKILL.md","line_end":53,"line_start":49}],"confidence":0.95,"description":"Static scanner flagged PHP code blocks as 'Ruby/shell backtick execution'. This is a false positive - the files contain legitimate Laravel PHP code examples, not shell commands.","confidence_reasoning":"PHP code blocks containing Laravel examples are clearly not shell execution. The scanner misinterprets PHP syntax as backtick commands."}],"low_findings":[{"title":"Weak Cryptographic Algorithm - False Positive","locations":[{"file":"references/eloquent.md","line_end":230,"line_start":68},{"file":"references/livewire.md","line_end":36,"line_start":19},{"file":"references/queues.md","line_end":338,"line_start":103},{"file":"references/routing.md","line_end":111,"line_start":8},{"file":"references/testing.md","line_end":516,"line_start":295},{"file":"SKILL.md","line_end":85,"line_start":3}],"confidence":0.95,"description":"Scanner flagged 'oldestOfMany()' and similar Laravel methods as 'weak cryptographic algorithm'. This is a false positive - these are standard Eloquent ORM methods.","confidence_reasoning":"The scanner misinterprets 'oldestOfMany' and similar method names as cryptographic issues. No encryption code exists in this skill."},{"title":"Environment Variable Access - False Positive","locations":[{"file":"references/queues.md","line_end":397,"line_start":396}],"confidence":0.95,"description":"Scanner flagged Laravel env() config calls as 'AWS credential environment variables'. This is standard Laravel configuration pattern - secure by design.","confidence_reasoning":"Using env() to read AWS credentials from environment is the recommended secure pattern in Laravel. No credential exfiltration present."},{"title":"Hardcoded URL - False Positive","locations":[{"file":"references/routing.md","line_end":356,"line_start":356},{"file":"references/testing.md","line_end":311,"line_start":311},{"file":"SKILL.md","line_end":6,"line_start":6}],"confidence":0.95,"description":"Scanner flagged test URLs in Laravel CORS config and HTTP testing. These are test/dummy URLs, not real external calls.","confidence_reasoning":"URLs like 'http://localhost:3000' and 'https://api.example.com/data' are test URLs for CORS and HTTP testing, not real network calls."},{"title":"System Reconnaissance - False Positive","locations":[{"file":"references/eloquent.md","line_end":350,"line_start":147},{"file":"references/livewire.md","line_end":470,"line_start":28},{"file":"references/queues.md","line_end":341,"line_start":30},{"file":"references/routing.md","line_end":157,"line_start":157},{"file":"references/testing.md","line_end":520,"line_start":16},{"file":"SKILL.md","line_end":60,"line_start":60}],"confidence":0.95,"description":"Scanner misinterprets Laravel Artisan commands and method names as system reconnaissance.","confidence_reasoning":"Laravel Artisan commands like 'php artisan' and method names are standard framework patterns, not reconnaissance tools."},{"title":"With Statement Detection - False Positive","locations":[{"file":"references/eloquent.md","line_end":229,"line_start":222},{"file":"references/livewire.md","line_end":497,"line_start":497},{"file":"references/routing.md","line_end":223,"line_start":83},{"file":"references/testing.md","line_end":202,"line_start":202}],"confidence":0.95,"description":"Scanner incorrectly flags Laravel's with() eager loading method as Python's deprecated 'with statement'.","confidence_reasoning":"with() is Laravel's Eloquent eager loading method, not Python's deprecated with statement. This is legitimate ORM syntax."}],"dangerous_patterns":[],"files_scanned":6,"total_lines":2265,"audit_model":"claude","audited_at":"2026-02-13T08:54:07.572+00:00","created_at":"2026-02-14T13:26:12.559684+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":6,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}