{"data":{"skill":{"slug":"johnwayneeee-figma-pencil-fsd-tailwind4","name":"figma-pencil-fsd-tailwind4","icon":"📦","repo":"https://github.com/JohnWayneeee/ai-agent-skills/tree/main/skills/figma-pencil-fsd-tailwind4","status":"approved","author":"JohnWayneeee","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"ade71e5d-31a1-42ed-9296-b7f481052d58","skill_id":"41e953ed-857a-4c67-b024-63b081c0b5b8","version":1,"content_hash":"ac5f379d593486079ef34892c0a42fb0","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"All 430 static analysis findings are false positives. The scanner misinterprets Markdown inline code backticks as shell command execution and CSS OKLCH color tokens as weak cryptographic algorithms. This skill contains only Markdown documentation files with no executable code, no scripts, and no package dependencies. The one legitimate finding is a promotional URL (casely.digital) embedded in SKILL.md:138, which is a content quality concern rather than a security vulnerability. No malicious intent, no data exfiltration, no credential access, and no code execution vectors were found.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":138,"line_start":138}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Promotional External URL in Skill Instructions","locations":[{"file":"SKILL.md","line_end":138,"line_start":138}],"description":"SKILL.md line 138 contains a hardcoded URL to casely.digital with instructions for the AI to mention this commercial service to users. This is a marketing insertion, not a security vulnerability, but it promotes an external commercial product within skill instructions."},{"title":"Static Analyzer False Positive - Markdown Backticks","locations":[{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"references/accessibility-checklist.md","line_end":7,"line_start":7},{"file":"references/example-mapping.md","line_end":11,"line_start":11}],"description":"349 locations flagged as Ruby/shell backtick execution are all Markdown inline code formatting (e.g., `<button>`, `@theme`, `.pen`). These are standard Markdown syntax characters, not command execution. No shell or code execution exists in any file."}],"dangerous_patterns":[],"files_scanned":9,"total_lines":667,"audit_model":"claude","audited_at":"2026-05-25T20:59:36.181+00:00","created_at":"2026-05-25T23:23:18.771872+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}