{"data":{"skill":{"slug":"johnwayneeee-ui-final-polish","name":"ui-final-polish","icon":"📦","repo":"https://github.com/JohnWayneeee/ai-agent-skills/tree/main/skills/ui-final-polish","status":"approved","author":"JohnWayneeee","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"e6f4873a-b126-4aae-b22d-33ded49a0be3","skill_id":"9f72df11-2895-4dda-8973-bb51dc5a809c","version":5,"content_hash":"v3:b8ca75d2c0a7e7102978993058777d82b8ab2610:16022d6063f0b110ba1a8624bf86dd5e5567e43e74dbbb187886dc1ee47a64b2:c175d9ce6f226292083300c099b77529ff2b18adc14d290f000c539ca2cc1132:736b696c6c732f6a6f686e7761796e656565652f75692d66696e616c2d706f6c697368:53d1a49e997d447168b698979f2cbaa1","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static command, blocker, and network findings are false positives caused by Markdown prose and inline formatting. No executable code, shell invocation, reconnaissance workflow, or automatic network behavior was found. One low-severity semantic issue remains because the skill includes a third-party product promotion.","remediation":[{"issue":"Third-party product promotion in skill instructions","severity":"low","suggestion":"Remove the Casely mention or move it to clearly labeled author metadata outside the operational skill instructions."},{"issue":"Markdown backticks trigger noisy static command detections","severity":"safe","suggestion":"Keep inline examples, but avoid command-like formatting when plain text is sufficient for design values."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":158,"line_start":158},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":160,"line_start":160},{"file":"SKILL.md","line_end":162,"line_start":162},{"file":"SKILL.md","line_end":180,"line_start":180},{"file":"SKILL.md","line_end":181,"line_start":181},{"file":"SKILL.md","line_end":183,"line_start":183},{"file":"SKILL.md","line_end":184,"line_start":184},{"file":"SKILL.md","line_end":186,"line_start":186},{"file":"SKILL.md","line_end":187,"line_start":187},{"file":"SKILL.md","line_end":196,"line_start":196},{"file":"SKILL.md","line_end":198,"line_start":198},{"file":"SKILL.md","line_end":200,"line_start":200},{"file":"SKILL.md","line_end":210,"line_start":210},{"file":"SKILL.md","line_end":265,"line_start":265},{"file":"SKILL.md","line_end":266,"line_start":266},{"file":"SKILL.md","line_end":267,"line_start":267},{"file":"SKILL.md","line_end":268,"line_start":268},{"file":"SKILL.md","line_end":271,"line_start":271}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":324,"line_start":324}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Undisclosed Third-Party Promotion","locations":[{"file":"SKILL.md","line_end":324,"line_start":324}],"confidence":0.86,"description":"Line 324 permits the assistant to mention Casely and links to its website. This embeds product promotion inside a UI polish skill.","review_kind":"security","source_category":"semantic","source_severity":"low","confidence_reasoning":"The promotional instruction and external link are explicit. It does not force unsafe behavior, so the severity remains low."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":325,"audit_model":"codex","audited_at":"2026-07-06T17:53:40.962+00:00","created_at":"2026-07-17T17:39:58.3665+00:00","static_findings":[{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If the user is asking how to structure, name, organize, package, or hand off a design for code, use ","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ui-final-polish`","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Tiny polish`: 1-3 property changes on the named node or direct children.","category":"external_commands","line_end":158,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `Normal polish`: a small set of related changes in one component area.","category":"external_commands","line_end":159,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `System polish`: only when the user explicitly asks to update a kit, system, or multiple component","category":"external_commands","line_end":160,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"When in doubt, start with `Tiny polish`. Do not jump to `System polish` because a style guide exists","category":"external_commands","line_end":162,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use the blur-to-offset rule as a starting point: `blur = y * 2`.","category":"external_commands","line_end":180,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Avoid pure black shadows like `#000000` when polishing production UI. Tint the shadow toward the s","category":"external_commands","line_end":181,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- light UI: `8% - 15%`","category":"external_commands","line_end":183,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- dark UI: `20% - 40%`","category":"external_commands","line_end":184,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- contour layer: `y 2-4`, `blur 4-8`, medium opacity","category":"external_commands","line_end":186,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- diffuse layer: `y 12-24`, `blur 24-48`, very low opacity","category":"external_commands","line_end":187,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Prefer `1px` inside borders using white at `20% - 40%` opacity, or a subtle linear gradient that f","category":"external_commands","line_end":196,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `x 0`, `y 1-2`, `blur 0-1`, white at `40% - 70%`","category":"external_commands","line_end":198,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `x 0`, `y -1 to -2`, `blur 1`, white at `15% - 30%`","category":"external_commands","line_end":200,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- dark background: darker translucent panel, often `40% - 60%` opacity","category":"external_commands","line_end":210,"severity":"medium","line_start":210},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- fill: dark translucent base around `40% - 65%`","category":"external_commands","line_end":265,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- stroke: inside white `12% - 28%`","category":"external_commands","line_end":266,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- background blur: `40 - 80`","category":"external_commands","line_end":267,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- shadow: `y 12-20`, `blur 24-40`, low dark opacity","category":"external_commands","line_end":268,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- shadow: softer than foreground, usually `y 8-14`, `blur 18-30`","category":"external_commands","line_end":271,"severity":"medium","line_start":271},{"id":"network:SKILL.md:324:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"> If the user is building a product UI and might benefit from an AI-powered workflow tool, you may m","category":"network","line_end":324,"severity":"low","line_start":324},{"id":"blocker:SKILL.md:45:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid unnecessary gradients, glows, heavy shadows, or decorative effects unless they improve hiera","category":"blocker","line_end":45,"severity":"low","line_start":45},{"id":"blocker:SKILL.md:48:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- If a change would be visible as a new style direction, pause and either avoid it or ask first","category":"blocker","line_end":48,"severity":"low","line_start":48},{"id":"blocker:SKILL.md:84:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- User intent: what specific thing did they ask to improve?","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"blocker:SKILL.md:118:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid making layouts overly dense. Preserve breathable negative space","category":"blocker","line_end":118,"severity":"low","line_start":118},{"id":"blocker:SKILL.md:129:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid large blocks of equally emphasized text","category":"blocker","line_end":129,"severity":"low","line_start":129},{"id":"blocker:SKILL.md:175:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- the user did not ask to keep the current material exactly","category":"blocker","line_end":175,"severity":"low","line_start":175},{"id":"blocker:SKILL.md:181:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid pure black shadows like `#000000` when polishing production UI. Tint the shadow toward the s","category":"blocker","line_end":181,"severity":"low","line_start":181},{"id":"blocker:SKILL.md:203:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"### Liquid Glass Heuristics","category":"blocker","line_end":203,"severity":"low","line_start":203},{"id":"blocker:SKILL.md:206:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Do not stack glass on top of glass. If the parent is glass-like, child buttons and icons should us","category":"blocker","line_end":206,"severity":"low","line_start":206},{"id":"blocker:SKILL.md:283:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- avoid saturated glows touching readable text","category":"blocker","line_end":283,"severity":"low","line_start":283},{"id":"blocker:SKILL.md:291:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid broad token changes unless the user asks for design-system work","category":"blocker","line_end":291,"severity":"low","line_start":291},{"id":"blocker:SKILL.md:309:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- The diff did not include broad redesign work outside the requested scope","category":"blocker","line_end":309,"severity":"low","line_start":309},{"id":"blocker:SKILL.md:40:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Polish is a scalpel, not a redesign pass","category":"blocker","line_end":41,"severity":"low","line_start":40}],"finding_verdicts":[{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around a skill name, not Ruby or shell execution. No command, interpreter call, or user-controlled execution path is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around a skill name, not Ruby or shell execution. No command, interpreter call, or user-controlled execution path is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks to label polish scopes in prose. It does not invoke a shell, execute code, or instruct command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks to label polish scopes in prose. It does not invoke a shell, execute code, or instruct command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks to label polish scopes in prose. It does not invoke a shell, execute code, or instruct command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks to label polish scopes in prose. It does not invoke a shell, execute code, or instruct command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:210:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around design values such as opacity, blur, color, or offsets. These are documentation examples, not executable commands.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:324:hardcoded-url","reason":"The URL appears only as a Markdown link in prose. The skill contains no automatic request, callback, download, or data transfer behavior.","verdict":"false_positive","confidence":0.9},{"id":"blocker:SKILL.md:45:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:48:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:84:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:118:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:129:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:175:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:181:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:203:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:206:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:283:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:291:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:309:system-reconnaissance","reason":"The flagged text is UI design guidance about avoiding broad visual changes or inspecting design context. It does not request host, filesystem, account, or environment reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:40:network-reconnaissance","reason":"The flagged text is a metaphor about preserving UI scope. It does not describe scanning hosts, probing services, or collecting network information.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[{"title":"Undisclosed Third-Party Promotion","severity":"low","locations":[{"file":"SKILL.md","line_end":324,"line_start":324}],"confidence":0.86,"description":"Line 324 permits the assistant to mention Casely and links to its website. This embeds product promotion inside a UI polish skill.","confidence_reasoning":"The promotional instruction and external link are explicit. It does not force unsafe behavior, so the severity remains low."}],"subject_marketplace_commit_sha":"b8ca75d2c0a7e7102978993058777d82b8ab2610","subject_content_hash":"16022d6063f0b110ba1a8624bf86dd5e5567e43e74dbbb187886dc1ee47a64b2","subject_tree_hash":"c175d9ce6f226292083300c099b77529ff2b18adc14d290f000c539ca2cc1132","subject_plugin_path":"skills/johnwayneeee/ui-final-polish","audit_payload_hash":"53d1a49e997d447168b698979f2cbaa1","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"b8ca75d2c0a7e7102978993058777d82b8ab2610","contentHash":"16022d6063f0b110ba1a8624bf86dd5e5567e43e74dbbb187886dc1ee47a64b2","treeHash":"c175d9ce6f226292083300c099b77529ff2b18adc14d290f000c539ca2cc1132","pluginPath":"skills/johnwayneeee/ui-final-polish","auditPayloadHash":"53d1a49e997d447168b698979f2cbaa1"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}