{"data":{"skill":{"slug":"moshuying-pitchcraft","name":"pitchcraft","icon":"📦","repo":"https://github.com/moshuying/pitchcraft/tree/main/","status":"approved","author":"moshuying","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"353a5ef6-5bee-4d94-b27d-226c507dd1f2","skill_id":"22aa96c5-2550-47c5-8fce-66824f59571f","version":5,"content_hash":"v3:02be9409c79ca1183f7844009c14d9df684d0cf9:58a5ff5f679c2f2d9cb06e10c0251768d8ca2a39460543e0fa350126da7e7efc:a3b77f432dae614d4a6dabb498f1bc7a23d5f5447d5f60abed3e4e08b4ac902c:736b696c6c732f6d6f73687579696e672f70697463686372616674:a6a05d08cb4b799c4bcaac0023016ece","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 31 static alerts are false positives caused by documentation, metadata URLs, Markdown formatting, installation paths, and normal Chinese text. One high-severity issue remains: package.json declares an automatic postinstall hook, but the referenced script is absent from the audited files.","remediation":[{"issue":"The npm postinstall hook executes scripts/install.js, which is missing from the audited file set.","severity":"high","suggestion":"Remove the lifecycle hook or include scripts/install.js in the submitted source so reviewers can verify its behavior before publication."}],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"LICENSE","line_end":3,"line_start":3},{"file":"package.json","line_end":11,"line_start":11},{"file":"package.json","line_end":13,"line_start":13},{"file":"package.json","line_end":14,"line_start":14},{"file":"README.md","line_end":84,"line_start":84},{"file":"README.zh-CN.md","line_end":86,"line_start":86}]},{"factor":"filesystem","evidence":[{"file":"README.md","line_end":62,"line_start":62},{"file":"README.md","line_end":62,"line_start":62},{"file":"README.zh-CN.md","line_end":64,"line_start":64},{"file":"README.zh-CN.md","line_end":64,"line_start":64}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":6,"line_start":6},{"file":"SKILL.md","line_end":51,"line_start":31},{"file":"SKILL.md","line_end":71,"line_start":51},{"file":"SKILL.md","line_end":101,"line_start":71},{"file":"SKILL.md","line_end":115,"line_start":101},{"file":"SKILL.md","line_end":138,"line_start":115},{"file":"SKILL.md","line_end":152,"line_start":138},{"file":"SKILL.md","line_end":176,"line_start":152},{"file":"SKILL.md","line_end":190,"line_start":176},{"file":"SKILL.md","line_end":214,"line_start":190},{"file":"SKILL.md","line_end":228,"line_start":214},{"file":"SKILL.md","line_end":251,"line_start":228},{"file":"SKILL.md","line_end":285,"line_start":251},{"file":"SKILL.md","line_end":354,"line_start":285}]}],"critical_findings":[],"high_findings":[{"title":"Unaudited Automatic Postinstall Hook","locations":[{"file":"package.json","line_end":37,"line_start":36}],"confidence":0.98,"description":"package.json registers node scripts/install.js as an automatic postinstall command, but that script is absent from the audited files. Its installation behavior cannot be verified.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The lifecycle hook is explicit in package.json, and the referenced script is not present in the audited file structure. npm runs postinstall commands automatically."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":6,"total_lines":912,"audit_model":"codex","audited_at":"2026-08-09T09:05:30.528+00:00","created_at":"2026-08-11T01:32:30.06072+00:00","static_findings":[{"id":"sensitive:.gitignore:5:npm-config-file-may-contain-tokens","file":".gitignore","pattern":"NPM config file (may contain tokens)","snippet":".npmrc","category":"sensitive","line_end":5,"severity":"high","line_start":5},{"id":"network:LICENSE:3:hardcoded-url","file":"LICENSE","pattern":"Hardcoded URL","snippet":"http://www.apache.org/licenses/","category":"network","line_end":3,"severity":"low","line_start":3},{"id":"network:package.json:11:hardcoded-url","file":"package.json","pattern":"Hardcoded URL","snippet":"\"url\": \"git+https://github.com/moshuying/pitchcraft.git\"","category":"network","line_end":11,"severity":"low","line_start":11},{"id":"network:package.json:13:hardcoded-url","file":"package.json","pattern":"Hardcoded URL","snippet":"\"homepage\": \"https://github.com/moshuying/pitchcraft#readme\",","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:package.json:14:hardcoded-url","file":"package.json","pattern":"Hardcoded URL","snippet":"\"bugs\": \"https://github.com/moshuying/pitchcraft/issues\",","category":"network","line_end":14,"severity":"low","line_start":14},{"id":"network:README.md:84:hardcoded-url","file":"README.md","pattern":"Hardcoded URL","snippet":"Install pitchcraft for me: https://github.com/moshuying/pitchcraft","category":"network","line_end":84,"severity":"low","line_start":84},{"id":"filesystem:README.md:62:hidden-file-in-home-directory","file":"README.md","pattern":"Hidden file in home directory","snippet":"# Global (~/.claude/skills/pitchcraft/)","category":"filesystem","line_end":62,"severity":"high","line_start":62},{"id":"filesystem:README.md:62:hidden-file-access","file":"README.md","pattern":"Hidden file access","snippet":"# Global (~/.claude/skills/pitchcraft/)","category":"filesystem","line_end":62,"severity":"medium","line_start":62},{"id":"blocker:README.md:91:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"[SkillsMP](https://skillsmp.com) auto-indexes repos with a root `SKILL.md` and valid frontmatter (`n","category":"blocker","line_end":91,"severity":"low","line_start":91},{"id":"blocker:README.md:184:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- Barbara Minto — _The Pyramid Principle_: conclusion first, MECE, hierarchy.","category":"blocker","line_end":184,"severity":"low","line_start":184},{"id":"blocker:README.md:194:system-reconnaissance","file":"README.md","pattern":"System reconnaissance","snippet":"- ❌ A repeat of _The Pyramid Principle_ — concrete, executable templates, not principles only","category":"blocker","line_end":194,"severity":"low","line_start":194},{"id":"network:README.zh-CN.md:86:hardcoded-url","file":"README.zh-CN.md","pattern":"Hardcoded URL","snippet":"Install pitchcraft for me: https://github.com/moshuying/pitchcraft","category":"network","line_end":86,"severity":"low","line_start":86},{"id":"filesystem:README.zh-CN.md:64:hidden-file-in-home-directory","file":"README.zh-CN.md","pattern":"Hidden file in home directory","snippet":"# 全局(~/.claude/skills/pitchcraft/)","category":"filesystem","line_end":64,"severity":"high","line_start":64},{"id":"filesystem:README.zh-CN.md:64:hidden-file-access","file":"README.zh-CN.md","pattern":"Hidden file access","snippet":"# 全局(~/.claude/skills/pitchcraft/)","category":"filesystem","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:6:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Languages:** English (this file) · 简体中文 → `SKILL.zh-CN.md`","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":51,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":101,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":115,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":138,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":152,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":176,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":190,"severity":"medium","line_start":176},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":214,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":228,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":251,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":285,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":354,"severity":"medium","line_start":285},{"id":"blocker:SKILL.md:146:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Hook | Goal attainment overview | Did we succeed overall? |","category":"blocker","line_end":146,"severity":"low","line_start":146},{"id":"blocker:SKILL.md:168:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- **What worked**: reusable methods / architecture / process","category":"blocker","line_end":169,"severity":"low","line_start":168},{"id":"obfuscation:README.zh-CN.md:1:heuristic-high-file-entropy-6-43-bits-possible-b","file":"README.zh-CN.md","pattern":"[HEURISTIC] High file entropy (6.43 bits) - possible binary/encrypted content","snippet":"File: README.zh-CN.md","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"sensitive:.gitignore:5:npm-config-file-may-contain-tokens","reason":"The line only ignores .npmrc to prevent accidental commits. It contains no token, credential, or sensitive configuration value.","verdict":"false_positive","confidence":0.99},{"id":"network:LICENSE:3:hardcoded-url","reason":"This is the standard Apache License reference URL. It is plain license text and does not initiate a network request.","verdict":"false_positive","confidence":1},{"id":"network:package.json:11:hardcoded-url","reason":"This URL identifies the package source repository in npm metadata. No runtime network operation uses it.","verdict":"false_positive","confidence":0.99},{"id":"network:package.json:13:hardcoded-url","reason":"This is the package homepage field in static metadata. It does not perform a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:package.json:14:hardcoded-url","reason":"This is the public issue tracker URL in package metadata. It does not transmit data or execute a request.","verdict":"false_positive","confidence":0.99},{"id":"network:README.md:84:hardcoded-url","reason":"The URL appears in a user-facing installation example and points to the declared GitHub repository. The documentation itself performs no network action.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:README.md:62:hidden-file-in-home-directory","reason":"The line documents the conventional Claude skills installation directory under the user's home directory. It does not read, write, or conceal files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.md:62:hidden-file-access","reason":"The hidden path is shown only in a comment explaining the global installation location. No filesystem access occurs on this line.","verdict":"false_positive","confidence":0.99},{"id":"blocker:README.md:91:system-reconnaissance","reason":"The line explains repository indexing requirements for SkillsMP. It contains no command or instruction to inspect a user's system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:README.md:184:system-reconnaissance","reason":"The phrase refers to the title The Pyramid Principle in a reading list. It has no system reconnaissance meaning.","verdict":"false_positive","confidence":1},{"id":"blocker:README.md:194:system-reconnaissance","reason":"The phrase again names The Pyramid Principle while describing the skill's scope. It does not request system information.","verdict":"false_positive","confidence":1},{"id":"network:README.zh-CN.md:86:hardcoded-url","reason":"The URL is the same public GitHub installation example shown in the Chinese documentation. It does not itself initiate network access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:README.zh-CN.md:64:hidden-file-in-home-directory","reason":"The Chinese documentation names the standard Claude skills directory as an installation destination. It does not access or hide user files.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:README.zh-CN.md:64:hidden-file-access","reason":"The path occurs only in a comment that explains global installation. There is no filesystem operation on this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:6:ruby-shell-backtick-execution","reason":"The backticks apply Markdown formatting to a translated filename. They do not represent Ruby or shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"This is the opening fence for a plain-text framework diagram. The enclosed content contains no executable command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"This line closes the plain-text framework diagram. A Markdown code fence does not execute shell commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"This fence opens a project kickoff writing template. The block contains placeholders and prose, not executable code.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"This line closes the project kickoff template. It has no command execution semantics.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"This fence opens a status update writing template. The content is structured prose with no shell or Ruby command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"This line closes the status update template. It is Markdown syntax only.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"This fence opens a wrap-up writing template containing headings, a table, and placeholders. It contains no executable command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"This line closes the wrap-up template. The backticks are a Markdown fence, not execution syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"This fence opens an investor pitch writing template. Its contents are prose placeholders and do not invoke external commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"This line closes the investor pitch template. It is inert Markdown formatting.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"This fence opens a solution selling writing template. The enclosed text contains no code or command invocation.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"This line closes the solution selling template. It does not execute any external process.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"This fence opens a plain-text workflow and checklist. The block describes writing steps without executable shell or Ruby instructions.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:146:system-reconnaissance","reason":"The phrase asks whether project goals were achieved in a review template. It does not inspect system state.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:168:network-reconnaissance","reason":"The word architecture describes reusable project lessons. It does not direct network discovery or scanning.","verdict":"false_positive","confidence":1},{"id":"obfuscation:README.zh-CN.md:1:heuristic-high-file-entropy-6-43-bits-possible-b","reason":"README.zh-CN.md is readable Simplified Chinese documentation. Its multilingual character distribution explains the entropy and is not encrypted or obfuscated content.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Unaudited Automatic Postinstall Hook","severity":"high","locations":[{"file":"package.json","line_end":37,"line_start":36}],"confidence":0.98,"description":"package.json registers node scripts/install.js as an automatic postinstall command, but that script is absent from the audited files. Its installation behavior cannot be verified.","confidence_reasoning":"The lifecycle hook is explicit in package.json, and the referenced script is not present in the audited file structure. npm runs postinstall commands automatically."}],"subject_marketplace_commit_sha":"02be9409c79ca1183f7844009c14d9df684d0cf9","subject_content_hash":"58a5ff5f679c2f2d9cb06e10c0251768d8ca2a39460543e0fa350126da7e7efc","subject_tree_hash":"a3b77f432dae614d4a6dabb498f1bc7a23d5f5447d5f60abed3e4e08b4ac902c","subject_plugin_path":"skills/moshuying/pitchcraft","audit_payload_hash":"a6a05d08cb4b799c4bcaac0023016ece","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"02be9409c79ca1183f7844009c14d9df684d0cf9","contentHash":"58a5ff5f679c2f2d9cb06e10c0251768d8ca2a39460543e0fa350126da7e7efc","treeHash":"a3b77f432dae614d4a6dabb498f1bc7a23d5f5447d5f60abed3e4e08b4ac902c","pluginPath":"skills/moshuying/pitchcraft","auditPayloadHash":"a6a05d08cb4b799c4bcaac0023016ece"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/moshuying-pitchcraft/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}