{"data":{"skill":{"slug":"rollinggo-ai-rollinggo-searchhotel","name":"rollinggo-searchhotel","icon":"📦","repo":"https://github.com/RollingGo-AI/rollinggo-skills/tree/main/rollinggo-hotel-cn/","status":"approved","author":"RollingGo-AI","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"71621a0e-abc9-4bb8-b1e2-315a48fdc286","skill_id":"68213739-2553-45b7-b747-093af333622f","version":2,"content_hash":"7ab406288fe8455ec111e7e081e40cdb","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis correctly detected external command examples, API key handling, network references, and host environment configuration. Review found no prompt injection or confirmed malicious intent, but the skill should publish with a warning because it directs agents to run latest third-party CLI packages and handle RollingGo_API_KEY.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":63,"line_start":57},{"file":"references/rollinggo-npx.md","line_end":30,"line_start":22},{"file":"references/rollinggo-uv.md","line_end":37,"line_start":25}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":13,"line_start":10},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"references/rollinggo-npx.md","line_end":79,"line_start":69},{"file":"references/rollinggo-uv.md","line_end":80,"line_start":70},{"file":"references/claw-host-env.md","line_end":18,"line_start":13}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"references/rollinggo-npx.md","line_end":84,"line_start":84},{"file":"references/rollinggo-uv.md","line_end":85,"line_start":85}]},{"factor":"filesystem","evidence":[{"file":"references/claw-host-env.md","line_end":32,"line_start":31}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Runtime Execution of Latest Third-Party CLI Packages","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":63,"line_start":57},{"file":"references/rollinggo-npx.md","line_end":30,"line_start":22},{"file":"references/rollinggo-uv.md","line_end":37,"line_start":25}],"confidence":0.86,"description":"The skill instructs agents to execute rollinggo@latest through npx or uvx. This is legitimate for the hotel workflow, but it creates supply-chain risk because the package resolved at runtime can change after review.","confidence_reasoning":"The command execution instructions are explicit and semantically required by the skill. The risk is supply-chain exposure from latest package resolution, not evidence of malicious code in the skill files."},{"title":"API Key Handling Through Environment and CLI Arguments","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":13,"line_start":10},{"file":"SKILL.md","line_end":45,"line_start":45},{"file":"references/rollinggo-npx.md","line_end":79,"line_start":69},{"file":"references/rollinggo-uv.md","line_end":80,"line_start":70}],"confidence":0.82,"description":"The skill requires RollingGo_API_KEY and documents passing it through environment variables or the --api-key option. This is expected for an authenticated API, but secrets can leak through shell history, logs, inherited environments, or host configuration if handled carelessly.","confidence_reasoning":"The files clearly require and document a real API key. The context is legitimate service authentication, but the exposure paths are common operational risks."}],"low_findings":[{"title":"Host Environment File Guidance Is Configuration Documentation","verdict":"FALSE_POSITIVE","locations":[{"file":"references/claw-host-env.md","line_end":32,"line_start":31}],"confidence":0.9,"description":"The scanner flagged hidden file access because the reference mentions .env paths and OpenClaw host configuration. The file only documents where users may store a key; it does not contain code that reads arbitrary files.","confidence_reasoning":"The relevant lines are documentation text about host configuration paths. No executable file-read logic or exfiltration path is present in the reviewed skill files."},{"title":"High Entropy Heuristic Appears to Be Natural Language Content","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":1,"line_start":1},{"file":"references/claw-host-env.md","line_end":1,"line_start":1},{"file":"references/rollinggo-npx.md","line_end":1,"line_start":1},{"file":"references/rollinggo-uv.md","line_end":1,"line_start":1}],"confidence":0.88,"description":"The scanner reported high entropy on the Markdown files. Review found normal Chinese and English documentation with command examples, not encoded payloads, binaries, encrypted blobs, or obfuscated scripts.","confidence_reasoning":"Manual review found Markdown documentation and examples only. No evidence of encoded content or hidden executable payloads was found."}],"dangerous_patterns":[{"title":"External Command Execution Examples","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":63,"line_start":57},{"file":"references/rollinggo-npx.md","line_end":30,"line_start":22},{"file":"references/rollinggo-uv.md","line_end":37,"line_start":25}],"confidence":0.87,"description":"Documentation directs agents to run rollinggo commands through npx, npm, uvx, uv, and local development commands. These are expected for the skill, but execution should be treated as running third-party code.","confidence_reasoning":"The command examples are explicit and repeated across the main skill and references. They are legitimate instructions, but still cross a code execution boundary."},{"title":"Secret Access Pattern for RollingGo_API_KEY","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":13,"line_start":10},{"file":"references/rollinggo-npx.md","line_end":79,"line_start":69},{"file":"references/rollinggo-uv.md","line_end":80,"line_start":70},{"file":"references/claw-host-env.md","line_end":18,"line_start":13}],"confidence":0.84,"description":"The skill tells users and agents to provide RollingGo_API_KEY through environment variables or command arguments. This is necessary for API access, but it should be isolated from logs and unrelated tools.","confidence_reasoning":"The secret name and configuration examples are directly present. The context is legitimate authentication, with no evidence that the skill itself steals the key."}],"files_scanned":4,"total_lines":584,"audit_model":"codex","audited_at":"2026-06-30T11:43:38.639+00:00","created_at":"2026-06-30T11:57:11.223942+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}