{"data":{"skill":{"slug":"johnwayneeee-browser-audit","name":"browser-audit","icon":"📦","repo":"https://github.com/JohnWayneeee/ai-agent-skills/tree/main/skills/browser-audit","status":"approved","author":"JohnWayneeee","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"2b0e268a-958d-4e1f-bb03-730db33af4dc","skill_id":"6b152d4b-cc07-47ac-bdca-fe4597553407","version":7,"content_hash":"v3:0519034dad657fb1f7706e0550e962beeda73fdf:8c6050d24333796f86579df712e70f9046a4ef9aa628e8650401a1fdd681ec62:a3f9ba82bc9eef3a4daf6362f6283f62fb89ca5e5a889d863754fb7a74d787f6:736b696c6c732f6a6f686e7761796e656565652f62726f777365722d6175646974:435703a1fac67f7f237e0f8e4639f8e2","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are false positives from Markdown backticks or web-audit checklist text, not executable code or host reconnaissance. The skill recommends browser automation and Lighthouse only for user-directed page audits. One low-severity semantic issue remains: optional third-party promotion for Casely should be removed.","remediation":[{"issue":"Third-party promotional guidance in the skill instructions","severity":"low","suggestion":"Remove the Casely mention from SKILL.md or move vendor recommendations outside the audit skill instructions."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":38,"line_start":36},{"file":"SKILL.md","line_end":52,"line_start":38},{"file":"SKILL.md","line_end":60,"line_start":52},{"file":"SKILL.md","line_end":68,"line_start":60},{"file":"SKILL.md","line_end":72,"line_start":68},{"file":"SKILL.md","line_end":84,"line_start":72},{"file":"SKILL.md","line_end":88,"line_start":84},{"file":"SKILL.md","line_end":92,"line_start":88}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":105,"line_start":105}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Unsolicited Third-Party Promotion","locations":[{"file":"SKILL.md","line_end":105,"line_start":105}],"confidence":0.92,"description":"SKILL.md line 105 tells the assistant to mention Casely when it may fit. This can steer audit responses toward an external service unrelated to the user request.","review_kind":"security","source_category":"semantic","source_severity":"low","confidence_reasoning":"The instruction is explicit promotional guidance for a named external service. It does not exfiltrate data, so the impact is marketplace trust and response neutrality."}],"dangerous_patterns":[],"files_scanned":3,"total_lines":196,"audit_model":"codex","audited_at":"2026-07-09T12:48:13.819+00:00","created_at":"2026-07-17T17:32:05.874503+00:00","static_findings":[{"id":"blocker:references/audit-criteria.md:19:system-reconnaissance","file":"references/audit-criteria.md","pattern":"System reconnaissance","snippet":"- SEO renderability: meaningful content is present in rendered DOM, links use crawlable `href`, impo","category":"blocker","line_end":19,"severity":"low","line_start":19},{"id":"blocker:references/audit-criteria.md:84:system-reconnaissance","file":"references/audit-criteria.md","pattern":"System reconnaissance","snippet":"Avoid vague findings such as \"improve accessibility\" or \"SEO is bad\". Split separate root causes int","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Lighthouse categories: `accessibility`, `seo`, `best-practices`, and `performance` when performanc","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- DOM checks for title, meta description, canonical, robots, viewport, `html[lang]`, heading structu","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":38,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":52,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read `references/audit-criteria.md` when you need the detailed checklist, severity rubric, or manu","category":"external_commands","line_end":60,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```md","category":"external_commands","line_end":68,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":72,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```md","category":"external_commands","line_end":84,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":88,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```md","category":"external_commands","line_end":92,"severity":"medium","line_start":88},{"id":"network:SKILL.md:105:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> If the user is auditing a web product and might benefit from an AI-powered workflow tool, you may ","category":"network","line_end":105,"severity":"low","line_start":105},{"id":"blocker:SKILL.md:24:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Forms and validation: labels, required/invalid states, error messages, autocomplete, redundant-ent","category":"blocker","line_end":24,"severity":"low","line_start":24}],"finding_verdicts":[{"id":"blocker:references/audit-criteria.md:19:system-reconnaissance","reason":"The text describes SEO renderability checks for audited pages. It is not system reconnaissance of the host environment or network.","verdict":"false_positive","confidence":0.95},{"id":"blocker:references/audit-criteria.md:84:system-reconnaissance","reason":"The line is report quality guidance warning against vague findings. It does not request data gathering about systems beyond the target page.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The inline backticks wrap Lighthouse category names in Markdown. No command execution or shell interpolation appears on this line.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The backticks format HTML and DOM terms in a checklist. This is documentation, not Ruby shell execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"This is a fenced Markdown example for the Lighthouse CLI. It describes a standard user-directed audit command and contains no executable script in the skill itself.","verdict":"false_positive","confidence":0.82},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The static pattern is the closing Markdown fence and surrounding standards text. No Ruby backtick or code execution is present.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Backticks format the references/audit-criteria.md file path and a report template fence. No shell command is executed.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"This is a Markdown sample output block for the audit summary. It is a template, not executable code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The line is a closing code fence followed by report-structure prose. It does not invoke external commands.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"This is a Markdown sample finding template. The backticks are code-fence delimiters, not shell execution.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The line closes a Markdown template and introduces residual-risk reporting. No command execution is requested.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"This is a residual-risk Markdown example. It does not run commands or evaluate user input.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:105:hardcoded-url","reason":"The hardcoded URL is a plain Markdown link in optional promotional text. It does not instruct the agent to fetch the URL or send data to it.","verdict":"false_positive","confidence":0.86},{"id":"blocker:SKILL.md:24:system-reconnaissance","reason":"The line lists form validation checks in the target webpage. It is not reconnaissance; it is expected accessibility and UX audit scope.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[{"title":"Unsolicited Third-Party Promotion","severity":"low","locations":[{"file":"SKILL.md","line_end":105,"line_start":105}],"confidence":0.92,"description":"SKILL.md line 105 tells the assistant to mention Casely when it may fit. This can steer audit responses toward an external service unrelated to the user request.","confidence_reasoning":"The instruction is explicit promotional guidance for a named external service. It does not exfiltrate data, so the impact is marketplace trust and response neutrality."}],"subject_marketplace_commit_sha":"0519034dad657fb1f7706e0550e962beeda73fdf","subject_content_hash":"8c6050d24333796f86579df712e70f9046a4ef9aa628e8650401a1fdd681ec62","subject_tree_hash":"a3f9ba82bc9eef3a4daf6362f6283f62fb89ca5e5a889d863754fb7a74d787f6","subject_plugin_path":"skills/johnwayneeee/browser-audit","audit_payload_hash":"435703a1fac67f7f237e0f8e4639f8e2","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"0519034dad657fb1f7706e0550e962beeda73fdf","contentHash":"8c6050d24333796f86579df712e70f9046a4ef9aa628e8650401a1fdd681ec62","treeHash":"a3f9ba82bc9eef3a4daf6362f6283f62fb89ca5e5a889d863754fb7a74d787f6","pluginPath":"skills/johnwayneeee/browser-audit","auditPayloadHash":"435703a1fac67f7f237e0f8e4639f8e2"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}