{"data":{"skill":{"slug":"juliusbrussee-megacave","name":"megacave","icon":"📦","repo":"https://github.com/juliusbrussee/caveman/tree/aeb45e2f787c0757a8af383a291a280cb6aeb4c1/skills/megacave","status":"approved","author":"juliusbrussee","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"e097a1ae-478a-49ac-ba0b-21ec46ca7805","skill_id":"0bd0c0e1-74e9-424e-9633-4fe95fde7041","version":1,"content_hash":"v3:38c2032d9c994f040745f35e98d3f24904b417cc:f25399c535a2f8f906e06cd0c5c52146b0e747abbf80e111c96f93adade04a69:03f7372a514d646dfb04c6bfcac41ccb9e1b56beddb2090044437be36895aaab:736b696c6c732f6a756c697573627275737365652f6d65676163617665:0bd55d0182a8ba2a1ea91a9c757ab7dc","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All six static findings are false positives: a relative documentation link and Markdown inline formatting do not execute commands or access files. No evidence found of prompt injection, credential access, or data exfiltration in the two reviewed files. The skill defines an explicit response style with safety and irreversible-action exceptions.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"README.md","line_end":7,"line_start":7}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":59,"line_start":59}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":76,"audit_model":"codex","audited_at":"2026-10-03T12:57:09.268+00:00","created_at":"2026-10-03T13:37:30.643414+00:00","static_findings":[{"id":"filesystem:README.md:7:path-traversal-sequence","file":"README.md","pattern":"Path traversal sequence","snippet":"**Characters, not tokens.** The reply on screen gets far shorter. The token bill moves much less: Me","category":"filesystem","line_end":7,"severity":"high","line_start":7},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every response, whole session, until \"stop caveman\" or \"normal mode\". Unsure? Still on. `/caveman st","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Good: \"每繪新生對象參照,故重繪;以 `useMemo` 包之則免。\"","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Good: \"新參照則重繪。`useMemo` 包之。\"","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Good: \"以 `useMemo` 包之。\"","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"白話 or the user's language, full sentences, then resume: security warning. Irreversible action, confi","category":"external_commands","line_end":59,"severity":"medium","line_start":59}],"finding_verdicts":[{"id":"filesystem:README.md:7:path-traversal-sequence","reason":"The parent-directory sequence appears only in a Markdown documentation link. No filesystem operation or instruction to access unauthorized files accompanies it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"Backticks format a status command and example status messages in Markdown prose. The line contains no Ruby or shell execution syntax in executable context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Backticks mark the useMemo identifier inside a Classical Chinese writing example. This is inline Markdown formatting, not executable command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The line demonstrates concise wording and formats useMemo as a technical identifier. No executable code or shell invocation is present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The writing example preserves useMemo with Markdown backticks instead of translating its name. The backticks do not appear in a program or shell context.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"Backticks format the caveman-compress command name within a prose exception list. The line requires clear security warnings and confirmation before irreversible actions, not command execution.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"38c2032d9c994f040745f35e98d3f24904b417cc","subject_content_hash":"f25399c535a2f8f906e06cd0c5c52146b0e747abbf80e111c96f93adade04a69","subject_tree_hash":"03f7372a514d646dfb04c6bfcac41ccb9e1b56beddb2090044437be36895aaab","subject_plugin_path":"skills/juliusbrussee/megacave","audit_payload_hash":"0bd55d0182a8ba2a1ea91a9c757ab7dc","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"38c2032d9c994f040745f35e98d3f24904b417cc","contentHash":"f25399c535a2f8f906e06cd0c5c52146b0e747abbf80e111c96f93adade04a69","treeHash":"03f7372a514d646dfb04c6bfcac41ccb9e1b56beddb2090044437be36895aaab","pluginPath":"skills/juliusbrussee/megacave","auditPayloadHash":"0bd55d0182a8ba2a1ea91a9c757ab7dc"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/juliusbrussee-megacave/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}