{"data":{"skill":{"slug":"shubhamsaboo-fullstack-developer","name":"fullstack-developer","icon":"📦","repo":"https://github.com/shubhamsaboo/awesome-llm-apps/tree/main/awesome_agent_skills/fullstack-developer","status":"approved","author":"shubhamsaboo","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"ebc169b6-4021-46c9-9458-4fa678e287fe","skill_id":"5bd89228-fb72-47b0-8c61-f88e83ffb30d","version":1,"content_hash":"v2:412e23e39ccd9729546286287b96bb41707397cf:d66f467c2b9feb83b61cac1086fc5eb0291347fec65eff8e09b615b9cd6ff0d6:2490fdd5d32ec8dacbbae507b8d92fce28010c4338edf756c72f57c3fcf32a01:a4f499da4bc0da62ec00969578d4d4a9","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Review found no malicious intent in SKILL.md. Static findings are false positives from Markdown fences, ordinary code examples, a relative fetch call, and benign technical guidance.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":69,"line_start":59},{"file":"SKILL.md","line_end":72,"line_start":69},{"file":"SKILL.md","line_end":81,"line_start":72},{"file":"SKILL.md","line_end":127,"line_start":81},{"file":"SKILL.md","line_end":165,"line_start":127},{"file":"SKILL.md","line_end":168,"line_start":165},{"file":"SKILL.md","line_end":184,"line_start":168},{"file":"SKILL.md","line_end":197,"line_start":184},{"file":"SKILL.md","line_end":214,"line_start":197},{"file":"SKILL.md","line_end":219,"line_start":214},{"file":"SKILL.md","line_end":221,"line_start":219},{"file":"SKILL.md","line_end":267,"line_start":221},{"file":"SKILL.md","line_end":270,"line_start":267},{"file":"SKILL.md","line_end":273,"line_start":270},{"file":"SKILL.md","line_end":276,"line_start":273},{"file":"SKILL.md","line_end":286,"line_start":276},{"file":"SKILL.md","line_end":289,"line_start":286},{"file":"SKILL.md","line_end":298,"line_start":289}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":184,"line_start":184}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":299,"audit_model":"codex","audited_at":"2026-07-07T02:40:50.715+00:00","created_at":"2026-07-07T06:05:36.288853+00:00","static_findings":[{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":69,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":72,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":81,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":127,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":165,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":168,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":184,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"queryFn: () => fetch(`/api/users/${userId}`).then(r => r.json()),","category":"external_commands","line_end":197,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":214,"severity":"medium","line_start":197},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":219,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":221,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":267,"severity":"medium","line_start":221},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":270,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":273,"severity":"medium","line_start":270},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":276,"severity":"medium","line_start":273},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```prisma","category":"external_commands","line_end":286,"severity":"medium","line_start":276},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":289,"severity":"medium","line_start":286},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":298,"severity":"medium","line_start":289},{"id":"network:SKILL.md:184:fetch-api-call","file":"SKILL.md","pattern":"Fetch API call","snippet":"queryFn: () => fetch(`/api/users/${userId}`).then(r => r.json()),","category":"network","line_end":184,"severity":"low","line_start":184},{"id":"blocker:SKILL.md:102:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid prop drilling","category":"blocker","line_end":102,"severity":"low","line_start":102},{"id":"blocker:SKILL.md:120:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Avoid N+1 queries","category":"blocker","line_end":120,"severity":"low","line_start":120},{"id":"blocker:SKILL.md:154:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"{ error: 'Invalid input', details: error.errors },","category":"blocker","line_end":154,"severity":"low","line_start":154},{"id":"blocker:SKILL.md:256:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"{ error: 'Invalid input', details: error.errors },","category":"blocker","line_end":256,"severity":"low","line_start":256},{"id":"blocker:SKILL.md:278:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"id        String   @id @default(cuid())","category":"blocker","line_end":278,"severity":"low","line_start":278}],"finding_verdicts":[{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"The backticks are a TypeScript template literal inside an example React fetch call, not shell execution. The request uses a relative API path and does not run external commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:197:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:221:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:270:ruby-shell-backtick-execution","reason":"This location is a fenced bash setup example in documentation, not automatic command execution. The skill presents dependency and Prisma setup instructions for the user to review.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:276:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:286:ruby-shell-backtick-execution","reason":"This finding points to a Markdown code fence or ordinary example block in SKILL.md, not Ruby or shell backtick execution. No hidden command execution instruction is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"This location is a fenced bash setup example in documentation, not automatic command execution. The skill presents dependency and Prisma setup instructions for the user to review.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:184:fetch-api-call","reason":"The fetch call is a client-side example that requests a relative application endpoint. It does not contact an external host or transmit secrets.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:102:system-reconnaissance","reason":"The text is React guidance to avoid prop drilling. It does not request host, network, process, or environment reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:120:system-reconnaissance","reason":"The text advises avoiding N+1 database queries for performance. It is not reconnaissance or system discovery behavior.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:154:system-reconnaissance","reason":"The snippet is an API validation error response in a code example. It does not gather or reveal host system information.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:256:system-reconnaissance","reason":"The snippet is an API validation error response in a code example. It does not gather or reveal host system information.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:278:system-reconnaissance","reason":"The snippet is a Prisma schema identifier field. It is database modeling syntax, not system reconnaissance.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}