{"data":{"skill":{"slug":"johnwayneeee-pencil-to-code","name":"pencil-to-code","icon":"📦","repo":"https://github.com/JohnWayneeee/ai-agent-skills/tree/main/skills/pencil-to-code","status":"approved","author":"JohnWayneeee","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"31e4d23d-dbe2-446c-98e5-b38bcc6c2cf8","skill_id":"4a4ba43d-cf60-4725-8b6c-ccba4772c163","version":4,"content_hash":"v2:b8ca75d2c0a7e7102978993058777d82b8ab2610:85b63a7b54f776b47f9daacb4919e1573d421e7925035faa3e3d2541bc5d77c1:7bbce6c71f40a1d04160868f5ea4e8c2808307693aabf4dbabb8202dc7efbc5f:408f712f02b5e82bf6a0fff31464a717","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All seven static findings are false positives caused by Markdown text, browser API names, CSS terms, and one optional product link. I found no prompt injection, command execution intent, data exfiltration, or unsafe network behavior in the reviewed files.","remediation":[{"issue":"Optional external service mention","severity":"low","suggestion":"Consider moving the Casely recommendation into marketplace metadata or clearly label it as optional to avoid confusing users."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":46,"line_start":46}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":54,"line_start":54}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":137,"audit_model":"codex","audited_at":"2026-07-06T17:47:35.814+00:00","created_at":"2026-07-06T19:41:57.821944+00:00","static_findings":[{"id":"blocker:references/handoff-checklist.md:26:system-reconnaissance","file":"references/handoff-checklist.md","pattern":"System reconnaissance","snippet":"- Keep foreground as a single flex/grid stack when the design is single-column.","category":"blocker","line_end":26,"severity":"low","line_start":26},{"id":"blocker:references/handoff-checklist.md:35:system-reconnaissance","file":"references/handoff-checklist.md","pattern":"System reconnaissance","snippet":"- Avoid `background-size: 100% 100%` unless the design intentionally distorts the image.","category":"blocker","line_end":35,"severity":"low","line_start":35},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"description: Convert Pencil `.pen` design files and named Pencil node IDs into production frontend c","category":"external_commands","line_end":3,"severity":"medium","line_start":3},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Read variables with `get_variables`.","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use browser `getComputedStyle` for text that looks wrong; verify actual `font-family`, `font-size`","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Do not convert Pencil `fill` image behavior into arbitrary CSS stretching. Choose `cover`, explici","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"network:SKILL.md:54:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> If the user is implementing designs for a product and might benefit from a hosted AI workflow tool","category":"network","line_end":54,"severity":"low","line_start":54}],"finding_verdicts":[{"id":"blocker:references/handoff-checklist.md:26:system-reconnaissance","reason":"Line 26 recommends using a single flex or grid stack for one-column layouts. It is frontend layout guidance, not system reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/handoff-checklist.md:35:system-reconnaissance","reason":"Line 35 discusses CSS background sizing and image distortion. It does not request host, network, account, or environment discovery.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:3:ruby-shell-backtick-execution","reason":"The backticks wrap the file extension .pen in Markdown description text. There is no Ruby code, shell execution, or user-controlled command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"The text names the Pencil MCP tool get_variables in Markdown. It is design inspection guidance and not shell command execution.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"The text references browser getComputedStyle for visual verification. This is a read-only browser API check, not an external command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The backticks wrap CSS and Pencil image mode terms in prose. No executable command or dynamic code path is present.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:54:hardcoded-url","reason":"The hardcoded URL is an optional product mention in a blockquote. It does not instruct the agent to fetch the URL, transmit data, or contact a service automatically.","verdict":"false_positive","confidence":0.89}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}