{"data":{"skill":{"slug":"jezweb-tanstack-query","name":"tanstack-query","icon":"📦","repo":"https://github.com/jezweb/claude-skills/tree/main/skills/tanstack-query/","status":"approved","author":"jezweb","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"fae0b292-d1af-4a3a-b48b-9d1b6db2d3a7","skill_id":"4fa325e6-00cb-4303-aabb-ac8c62e0a382","version":2,"content_hash":"5e19fb0880ba003bae4e972cae2ca26d","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported a critical combined-risk heuristic, but the reviewed evidence is documentation and template code for TanStack Query usage. No malicious intent, prompt injection, credential exfiltration, or real command execution was found; remaining concerns are normal network examples and a placeholder shell script.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"templates/use-query-basic.tsx","line_end":24,"line_start":17},{"file":"templates/use-mutation-basic.tsx","line_end":33,"line_start":22},{"file":"templates/custom-hooks-pattern.tsx","line_end":38,"line_start":20},{"file":"templates/use-infinite-query.tsx","line_end":33,"line_start":20},{"file":"templates/error-boundary.tsx","line_end":188,"line_start":166}]},{"factor":"scripts","evidence":[{"file":"scripts/example-script.sh","line_end":15,"line_start":1},{"file":"templates/devtools-setup.tsx","line_end":190,"line_start":173}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Markdown Code Fence Detections Are False Positives","locations":[{"file":"SKILL.md","line_end":42,"line_start":24},{"file":"rules/tanstack-query.md","line_end":21,"line_start":11},{"file":"README.md","line_end":86,"line_start":79}],"confidence":0.93,"description":"The many external command and weak-crypto detections are from Markdown code fences, migration tables, and TypeScript examples. Reviewed locations show educational TanStack Query snippets, not executable shell or Ruby code.","confidence_reasoning":"The cited lines are documentation or fenced TypeScript examples. No shell interpolation, runtime execution path, or cryptographic operation is present in the reviewed context."},{"title":"Template Network Calls Are Expected Examples","locations":[{"file":"templates/use-query-basic.tsx","line_end":24,"line_start":17},{"file":"templates/use-mutation-basic.tsx","line_end":33,"line_start":22},{"file":"templates/custom-hooks-pattern.tsx","line_end":38,"line_start":20}],"confidence":0.86,"description":"The templates use fetch calls to JSONPlaceholder and local API paths to demonstrate queries and mutations. This is legitimate for a data-fetching skill, but users should replace sample endpoints before production use.","confidence_reasoning":"The network calls are clear tutorial endpoints and normal API examples. They do not include secrets or hidden destinations, but copied templates can perform outbound requests."},{"title":"Placeholder Script Has No Harmful Logic","locations":[{"file":"scripts/example-script.sh","line_end":15,"line_start":1}],"confidence":0.9,"description":"The shell script is a placeholder with set -e and an echo statement. It is safe as shipped, but marketplaces should still label the skill as containing a script file.","confidence_reasoning":"The complete script contains only comments, set -e, and a static echo. There is no command injection vector, file modification, network access, or credential access."},{"title":"DevTools Sensitive-Access Detections Are Benign","locations":[{"file":"templates/devtools-setup.tsx","line_end":78,"line_start":64},{"file":"templates/devtools-setup.tsx","line_end":220,"line_start":207},{"file":"templates/devtools-setup.tsx","line_end":248,"line_start":231}],"confidence":0.88,"description":"The environment and key-file alerts map to import.meta.env.DEV and KeyboardEvent key handling in a DevTools example. These are normal frontend checks, not environment file reads or certificate access.","confidence_reasoning":"The reviewed lines use a development-mode boolean and keyboard shortcut handling. The same file warns not to expose production DevTools or sensitive cache data."}],"dangerous_patterns":[],"files_scanned":22,"total_lines":4893,"audit_model":"codex","audited_at":"2026-06-30T04:24:17.174+00:00","created_at":"2026-06-30T04:44:54.480574+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}