{"data":{"skill":{"slug":"shubhamsaboo-project-planner","name":"project-planner","icon":"📦","repo":"https://github.com/shubhamsaboo/awesome-llm-apps/tree/main/awesome_agent_skills/project-planner","status":"approved","author":"shubhamsaboo","authorVersion":"1.0.0","skillstoreRevision":1},"audit":{"id":"c2a5d781-8eb4-46c0-ad72-cd5293f83820","skill_id":"e1ee9a5d-79d3-414d-8300-bde8a8d5e03b","version":2,"content_hash":"v3:412e23e39ccd9729546286287b96bb41707397cf:ea1efbc2797ce4b9d5c60d7a31f72c7106b503f2b2e16910bde3ca5c35abb530:f0165af92c892c875246d30560b5a3937af575777ee5042b18efcc0f4695da96:736b696c6c732f7368756268616d7361626f6f2f70726f6a6563742d706c616e6e6572:a0a3d0cfaa6af6c9d27247dd5c77e925","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static findings are false positives caused by Markdown code fences and task-sizing guidance in SKILL.md. I found no evidence of executable shell commands, network reconnaissance, prompt injection, data exfiltration, or malicious intent.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":118,"line_start":87},{"file":"SKILL.md","line_end":121,"line_start":118},{"file":"SKILL.md","line_end":138,"line_start":121},{"file":"SKILL.md","line_end":143,"line_start":138},{"file":"SKILL.md","line_end":149,"line_start":143},{"file":"SKILL.md","line_end":254,"line_start":149},{"file":"SKILL.md","line_end":257,"line_start":254}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":302,"audit_model":"codex","audited_at":"2026-07-07T02:55:26.838+00:00","created_at":"2026-07-15T09:07:21.626727+00:00","static_findings":[{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":118,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":121,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":138,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":143,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":149,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":254,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":257,"severity":"medium","line_start":254},{"id":"blocker:SKILL.md:71:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- Difficult to track progress","category":"blocker","line_end":72,"severity":"low","line_start":71}],"finding_verdicts":[{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"Line 87 starts a Markdown example block for the documented output format. It is documentation text and does not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"Line 118 is a Markdown fence inside a dependency map example. The surrounding lines show plain diagram text, not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"Line 121 closes the Markdown dependency diagram block. No command string, interpreter call, or user-controlled execution path is present.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"Line 138 closes the documented Markdown output template. It is static formatting guidance and cannot execute commands.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"Line 143 opens a Markdown block for the three-point estimation formula. The block contains plain estimation text, not Ruby backtick execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"Line 149 closes the estimation formula Markdown block. There is no executable command or external process invocation.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","reason":"Line 254 opens a Markdown block for a dependency visualization example. It contains a static planning diagram, not shell or Ruby execution.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:71:network-reconnaissance","reason":"Lines 71-72 discuss why oversized tasks are difficult to track and can block work. This is project planning prose with no network scanning or reconnaissance behavior.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"412e23e39ccd9729546286287b96bb41707397cf","subject_content_hash":"ea1efbc2797ce4b9d5c60d7a31f72c7106b503f2b2e16910bde3ca5c35abb530","subject_tree_hash":"f0165af92c892c875246d30560b5a3937af575777ee5042b18efcc0f4695da96","subject_plugin_path":"skills/shubhamsaboo/project-planner","audit_payload_hash":"a0a3d0cfaa6af6c9d27247dd5c77e925","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"412e23e39ccd9729546286287b96bb41707397cf","contentHash":"ea1efbc2797ce4b9d5c60d7a31f72c7106b503f2b2e16910bde3ca5c35abb530","treeHash":"f0165af92c892c875246d30560b5a3937af575777ee5042b18efcc0f4695da96","pluginPath":"skills/shubhamsaboo/project-planner","auditPayloadHash":"a0a3d0cfaa6af6c9d27247dd5c77e925"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}