{"data":{"skill":{"slug":"jetbrains-doc-sync","name":"doc-sync","icon":"📦","repo":"https://github.com/JetBrains/ideavim/tree/master/.claude/skills/doc-sync","status":"approved","author":"JetBrains","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"a85d8f09-b7b6-41f3-b4a4-c37d3b47f857","skill_id":"129700a9-c9bc-4b9b-b2f4-9e146c27e542","version":9,"content_hash":"v3:ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006:3a9e99354402998062449dd97db817472a02e51e6c75b277326eff93892d8e3f:db135dc38c38354c1617788b033c330d8aca716168bb5ca743d3032d4992448a:736b696c6c732f6a6574627261696e732f646f632d73796e63:bb315a90a342e6821a0bc6eb9d228ef5","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 18 backtick findings are false positives caused by Markdown formatting or documented, read-only search and Git commands. The network-scanning finding is also false because nmap appears only as text inside a grep pattern.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":40,"line_start":34},{"file":"SKILL.md","line_end":44,"line_start":40},{"file":"SKILL.md","line_end":53,"line_start":44},{"file":"SKILL.md","line_end":56,"line_start":53},{"file":"SKILL.md","line_end":62,"line_start":56},{"file":"SKILL.md","line_end":139,"line_start":62},{"file":"SKILL.md","line_end":140,"line_start":139},{"file":"SKILL.md","line_end":179,"line_start":140},{"file":"SKILL.md","line_end":190,"line_start":179},{"file":"SKILL.md","line_end":193,"line_start":190},{"file":"SKILL.md","line_end":207,"line_start":193},{"file":"SKILL.md","line_end":210,"line_start":207},{"file":"SKILL.md","line_end":223,"line_start":210},{"file":"SKILL.md","line_end":229,"line_start":223},{"file":"SKILL.md","line_end":250,"line_start":229}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":276,"audit_model":"codex","audited_at":"2026-07-23T15:33:45.745+00:00","created_at":"2026-07-25T12:07:05.23958+00:00","static_findings":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `doc/` folder - Detailed documentation files","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `README.md` - Main project README","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `CONTRIBUTING.md` - Contribution guidelines","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":40,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":44,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":53,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":56,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":62,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":139,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Check git history:** Run `git log -10` on changed files, look for \"remove\" commits","category":"external_commands","line_end":140,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Understand deletions:** Run `git show [commit]` to see what was removed","category":"external_commands","line_end":179,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":190,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":193,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":207,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":210,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":223,"severity":"medium","line_start":210},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":229,"severity":"medium","line_start":223},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":250,"severity":"medium","line_start":229},{"id":"blocker:SKILL.md:61:network-scanning-tools","file":"SKILL.md","pattern":"Network scanning tools","snippet":"grep -E 'fun \\w+\\(|nmap\\(|vmap\\(|map\\(' doc/*.md -B1 -A3","category":"blocker","line_end":61,"severity":"high","line_start":61}],"finding_verdicts":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The backticks format the doc/ path as inline Markdown. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The backticks format the README.md filename as inline Markdown. No command is executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The backticks format the CONTRIBUTING.md filename as inline Markdown. No shell execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The detected text is a Markdown fence around documented grep and find examples. It is not Ruby backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The detected backticks close a Markdown code block. They have no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The Markdown block documents read-only git log and git show inspection commands. It contains no Ruby backtick expression or command injection path.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The detected backticks close a Markdown code block. They do not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The Markdown fence introduces documented grep searches over local documentation. It is not a Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The detected backticks close a Markdown code block before ordinary workflow prose. No command execution occurs at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The backticks format a read-only git log command in documentation. This is legitimate repository inspection without dynamic shell construction.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The backticks format a read-only git show command in documentation. The placeholder is instructional and no executable interpolation is defined.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The detected backticks delimit a plain-text usage example. They are Markdown formatting, not command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The detected backticks close a plain-text example block. No shell or Ruby expression is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The backticks open a Markdown example describing repository inspection steps. The listed Git searches are read-only and contain no command injection mechanism.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"The detected backticks close a Markdown example block. They do not trigger external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","reason":"The backticks open a plain-text workflow example. The content is descriptive and not an executable shell block.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"The detected backticks close a plain-text workflow example. They are Markdown syntax only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:229:ruby-shell-backtick-execution","reason":"The backticks open the requested documentation report template. The block contains placeholders and report headings, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:61:network-scanning-tools","reason":"The token nmap appears inside a grep regular expression used to find mapping calls in local Markdown files. The skill does not invoke nmap or perform network scanning.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","subject_content_hash":"3a9e99354402998062449dd97db817472a02e51e6c75b277326eff93892d8e3f","subject_tree_hash":"db135dc38c38354c1617788b033c330d8aca716168bb5ca743d3032d4992448a","subject_plugin_path":"skills/jetbrains/doc-sync","audit_payload_hash":"bb315a90a342e6821a0bc6eb9d228ef5","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","contentHash":"3a9e99354402998062449dd97db817472a02e51e6c75b277326eff93892d8e3f","treeHash":"db135dc38c38354c1617788b033c330d8aca716168bb5ca743d3032d4992448a","pluginPath":"skills/jetbrains/doc-sync","auditPayloadHash":"bb315a90a342e6821a0bc6eb9d228ef5"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/jetbrains-doc-sync/audits/9/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}