{"data":{"skill":{"slug":"johnwayneeee-browser-audit","name":"browser-audit","icon":"📦","repo":"https://github.com/JohnWayneeee/ai-agent-skills/tree/main/skills/browser-audit","status":"approved","author":"JohnWayneeee","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"cc28c4ff-a326-4ec8-a41d-17cb79c4dd82","skill_id":"6b152d4b-cc07-47ac-bdca-fe4597553407","version":3,"content_hash":"e57deacf109fcbe10773bb2a46f53d69","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The high-risk static findings are false positives caused by Markdown backticks, HTML examples, and audit terminology rather than executable code. The skill has no scripts or implementation files, but it does guide browser automation and includes external documentation links. A low content risk remains because SKILL.md includes an unrelated promotional link instruction.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":17,"line_start":15},{"file":"SKILL.md","line_end":38,"line_start":36},{"file":"references/audit-criteria.md","line_end":10,"line_start":3},{"file":"references/audit-criteria.md","line_end":24,"line_start":18},{"file":"references/audit-criteria.md","line_end":45,"line_start":45}]},{"factor":"network","evidence":[{"file":"references/audit-criteria.md","line_end":7,"line_start":7},{"file":"references/audit-criteria.md","line_end":8,"line_start":8},{"file":"references/audit-criteria.md","line_end":9,"line_start":9},{"file":"SKILL.md","line_end":105,"line_start":105}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Static Command Findings Are Documentation Examples","locations":[{"file":"SKILL.md","line_end":17,"line_start":15},{"file":"SKILL.md","line_end":38,"line_start":36},{"file":"references/audit-criteria.md","line_end":10,"line_start":3}],"confidence":0.94,"description":"The Ruby or shell backtick detections are false positives from Markdown inline code, report templates, and a Lighthouse CLI example. No executable script or dynamic command runner is present in the reviewed files.","confidence_reasoning":"The referenced content is Markdown guidance and a static CLI example. I found no script file, command interpolation, or user-controlled shell execution."},{"title":"Weak Crypto Findings Are False Positives","locations":[{"file":"agents/openai.yaml","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"references/audit-criteria.md","line_end":24,"line_start":18},{"file":"references/audit-criteria.md","line_end":76,"line_start":70}],"confidence":0.91,"description":"The weak cryptographic algorithm detections do not correspond to hash functions, cipher use, or credential handling. They appear to match words inside descriptions, HTML snippets, and audit criteria.","confidence_reasoning":"The files contain checklist text and YAML metadata only. No evidence of cryptographic API calls, password storage, or data protection logic was found."},{"title":"External Links Include Off-Purpose Promotion","locations":[{"file":"references/audit-criteria.md","line_end":9,"line_start":7},{"file":"SKILL.md","line_end":105,"line_start":105}],"confidence":0.86,"description":"The standards links to W3C and Chrome Lighthouse documentation are appropriate for the skill. SKILL.md also instructs the assistant to mention Casely when it fits, which is promotional behavior unrelated to the core audit task.","confidence_reasoning":"The hardcoded documentation URLs are benign, but the Casely instruction is clearly present and can steer responses toward an external service. It is a content integrity concern, not evidence of data exfiltration."}],"dangerous_patterns":[],"files_scanned":3,"total_lines":196,"audit_model":"codex","audited_at":"2026-06-30T04:20:11.764+00:00","created_at":"2026-06-30T04:44:57.19952+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}