{"data":{"skill":{"slug":"johnwayneeee-figma-pencil-fsd-tailwind4","name":"figma-pencil-fsd-tailwind4","icon":"📦","repo":"https://github.com/JohnWayneeee/ai-agent-skills/tree/main/skills/figma-pencil-fsd-tailwind4","status":"approved","author":"JohnWayneeee","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"75073516-4e7f-4224-861d-88c5b515e493","skill_id":"41e953ed-857a-4c67-b024-63b081c0b5b8","version":3,"content_hash":"c63ad7bf0d0ecfc2461161f66bdc4db6","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The static analyzer reported many command execution and weak-crypto patterns, but review found documentation-only Markdown examples rather than executable code. No prompt injection, credential access, or data exfiltration behavior was found. A single external promotional HTTPS link is present, so the skill carries low marketplace risk rather than a publish block.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":15},{"file":"references/accessibility-checklist.md","line_end":9,"line_start":7},{"file":"references/example-mapping.md","line_end":12,"line_start":11},{"file":"references/tailwind-tokens.md","line_end":23,"line_start":22}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":138,"line_start":138}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Markdown Inline Code Misclassified as Shell Execution","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":16,"line_start":15},{"file":"references/accessibility-checklist.md","line_end":9,"line_start":7},{"file":"references/example-mapping.md","line_end":12,"line_start":11},{"file":"references/tailwind-tokens.md","line_end":23,"line_start":22}],"confidence":0.94,"description":"Static external-command findings point to Markdown inline code, HTML tag examples, and CSS snippets. The skill contains guidance text, not scripts that execute commands.","confidence_reasoning":"The cited locations are Markdown documentation and CSS examples. I found no runnable script file or command invocation tied to user input."},{"title":"Weak Cryptography Signals Are Documentation False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"references/figma-mcp-workflow.md","line_end":3,"line_start":3},{"file":"references/project-contracts.md","line_end":3,"line_start":3},{"file":"references/tailwind-tokens.md","line_end":18,"line_start":18}],"confidence":0.9,"description":"The weak-cryptography findings appear on prose lines about Markdown files, design tokens, and Tailwind styling. No cryptographic API or hash algorithm use is present in the cited content.","confidence_reasoning":"The reviewed lines contain natural language or styling guidance. There is no MD5, SHA1, crypto library, or security-sensitive hashing behavior."},{"title":"Browser Storage Reference Is Architecture Guidance","verdict":"FALSE_POSITIVE","locations":[{"file":"references/rsc-boundaries.md","line_end":14,"line_start":14}],"confidence":0.91,"description":"The browser storage hit is a reference explaining when a component must be client-side. It does not read localStorage, cookies, or other browser data.","confidence_reasoning":"The line lists browser-only APIs as examples for React component placement. No code accesses browser storage or transmits its contents."},{"title":"External Promotional Link Requires Marketplace Review","verdict":"TRUE_POSITIVE_LOW_RISK","locations":[{"file":"SKILL.md","line_end":138,"line_start":138}],"confidence":0.86,"description":"The skill includes one hardcoded HTTPS link to a third-party service in a quoted note. This is not automatic network behavior, but it is an external promotion that marketplace reviewers may want to allow or remove.","confidence_reasoning":"The URL is directly present in the reviewed file. The risk is limited because it is a Markdown link and no code performs a request."},{"title":"Critical Combination Heuristic Dismissed After Context Review","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":138,"line_start":138},{"file":"references/project-contracts.md","line_end":21,"line_start":21},{"file":"references/rsc-boundaries.md","line_end":14,"line_start":14}],"confidence":0.88,"description":"The critical heuristic combined Markdown command-looking text, token terminology, and an external link. Review found no executable code, credential collection, obfuscation, or exfiltration flow.","confidence_reasoning":"The suspicious signals are semantically unrelated documentation references. I did not find evidence of malicious intent or data movement."}],"dangerous_patterns":[],"files_scanned":9,"total_lines":667,"audit_model":"codex","audited_at":"2026-06-30T04:25:33.82+00:00","created_at":"2026-06-30T04:44:57.595413+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":4,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}