{"data":{"skill":{"slug":"sickn33-azure-monitor-opentelemetry-ts","name":"azure-monitor-opentelemetry-ts","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/azure-monitor-opentelemetry-ts","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"370ff92b-8de6-4aa1-bae6-133a0a394167","skill_id":"6e599984-bdea-4193-9e93-853a480028df","version":5,"content_hash":"v3:f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526:c4ff113940cc207dc0db8fd184fd236a3ae5c1bb782a4362eb0e8b350d8ce1cf:ee275fc8e68241736d77057440e60f257e3cd1857bf7fbcf2e53b403a7a7a926:736b696c6c732f7369636b6e33332f617a7572652d6d6f6e69746f722d6f70656e74656c656d657472792d7473:dd466fee20eefa1d98e2c355a5edee39","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 52 static findings are false positives caused by Markdown code fences, expected Azure Monitor examples, and OpenTelemetry method names. The skill contains documentation only, with no executable scripts, prompt injection, credential harvesting, or undeclared network destination.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":24,"line_start":15},{"file":"SKILL.md","line_end":28,"line_start":24},{"file":"SKILL.md","line_end":30,"line_start":28},{"file":"SKILL.md","line_end":34,"line_start":30},{"file":"SKILL.md","line_end":36,"line_start":34},{"file":"SKILL.md","line_end":48,"line_start":36},{"file":"SKILL.md","line_end":52,"line_start":48},{"file":"SKILL.md","line_end":54,"line_start":52},{"file":"SKILL.md","line_end":57,"line_start":54},{"file":"SKILL.md","line_end":63,"line_start":57},{"file":"SKILL.md","line_end":67,"line_start":63},{"file":"SKILL.md","line_end":103,"line_start":67},{"file":"SKILL.md","line_end":107,"line_start":103},{"file":"SKILL.md","line_end":126,"line_start":107},{"file":"SKILL.md","line_end":130,"line_start":126},{"file":"SKILL.md","line_end":148,"line_start":130},{"file":"SKILL.md","line_end":154,"line_start":148},{"file":"SKILL.md","line_end":167,"line_start":154},{"file":"SKILL.md","line_end":171,"line_start":167},{"file":"SKILL.md","line_end":185,"line_start":171},{"file":"SKILL.md","line_end":189,"line_start":185},{"file":"SKILL.md","line_end":202,"line_start":189},{"file":"SKILL.md","line_end":206,"line_start":202},{"file":"SKILL.md","line_end":234,"line_start":206},{"file":"SKILL.md","line_end":238,"line_start":234},{"file":"SKILL.md","line_end":262,"line_start":238},{"file":"SKILL.md","line_end":266,"line_start":262},{"file":"SKILL.md","line_end":274,"line_start":266},{"file":"SKILL.md","line_end":278,"line_start":274},{"file":"SKILL.md","line_end":288,"line_start":278},{"file":"SKILL.md","line_end":292,"line_start":288},{"file":"SKILL.md","line_end":312,"line_start":292},{"file":"SKILL.md","line_end":317,"line_start":312},{"file":"SKILL.md","line_end":321,"line_start":317}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":210,"line_start":210}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":177,"line_start":177},{"file":"SKILL.md","line_end":195,"line_start":195},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":159,"line_start":159},{"file":"SKILL.md","line_end":177,"line_start":177},{"file":"SKILL.md","line_end":195,"line_start":195}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":330,"audit_model":"codex","audited_at":"2026-07-23T22:01:23.409+00:00","created_at":"2026-07-26T06:20:43.586189+00:00","static_findings":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":24,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":30,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":34,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**IMPORTANT:** Call `useAzureMonitor()` BEFORE importing other modules.","category":"external_commands","line_end":36,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":48,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":52,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":54,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":57,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":63,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":67,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":103,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":107,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":126,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":130,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":148,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":154,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":167,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":171,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":185,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":189,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":202,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":206,"severity":"medium","line_start":202},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":234,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":238,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":262,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":266,"severity":"medium","line_start":262},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":274,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":278,"severity":"medium","line_start":274},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":288,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":292,"severity":"medium","line_start":288},{"id":"external_commands:SKILL.md:292:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":312,"severity":"medium","line_start":292},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":317,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Use ESM loader for ESM projects** - `--import @azure/monitor-opentelemetry/loader`","category":"external_commands","line_end":321,"severity":"medium","line_start":317},{"id":"network:SKILL.md:210:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"const endpoint = \"https://<dce>.ingest.monitor.azure.com\";","category":"network","line_end":210,"severity":"low","line_start":210},{"id":"env_access:SKILL.md:41:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":41,"severity":"low","line_start":41},{"id":"env_access:SKILL.md:73:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING,","category":"env_access","line_end":73,"severity":"low","line_start":73},{"id":"env_access:SKILL.md:159:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":159,"severity":"low","line_start":159},{"id":"env_access:SKILL.md:177:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":177,"severity":"low","line_start":177},{"id":"env_access:SKILL.md:195:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":195,"severity":"low","line_start":195},{"id":"env_access:SKILL.md:41:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":41,"severity":"low","line_start":41},{"id":"env_access:SKILL.md:73:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING,","category":"env_access","line_end":73,"severity":"low","line_start":73},{"id":"env_access:SKILL.md:159:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":159,"severity":"low","line_start":159},{"id":"env_access:SKILL.md:177:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":177,"severity":"low","line_start":177},{"id":"env_access:SKILL.md:195:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"env_access","line_end":195,"severity":"low","line_start":195},{"id":"sensitive:SKILL.md:41:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"sensitive","line_end":41,"severity":"high","line_start":41},{"id":"sensitive:SKILL.md:73:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING,","category":"sensitive","line_end":73,"severity":"high","line_start":73},{"id":"sensitive:SKILL.md:159:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"sensitive","line_end":159,"severity":"high","line_start":159},{"id":"sensitive:SKILL.md:177:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"sensitive","line_end":177,"severity":"high","line_start":177},{"id":"sensitive:SKILL.md:195:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"connectionString: process.env.APPLICATIONINSIGHTS_CONNECTION_STRING","category":"sensitive","line_end":195,"severity":"high","line_start":195},{"id":"blocker:SKILL.md:246:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"onStart(span: Span, context: Context): void {}","category":"blocker","line_end":246,"severity":"low","line_start":246},{"id":"blocker:SKILL.md:248:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"onEnd(span: ReadableSpan): void {","category":"blocker","line_end":248,"severity":"low","line_start":248}],"finding_verdicts":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"Line 15 opens a fenced Bash example containing documented npm installation commands. Markdown backticks do not execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"Line 24 only closes the installation example's Markdown code fence. It is not Ruby or shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"Line 28 opens a fenced environment-variable example. The backticks are Markdown syntax and cannot execute the displayed text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"Line 30 only closes a Markdown code fence. No execution primitive is present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"Line 34 uses inline Markdown to name the useAzureMonitor function. It does not invoke Ruby, a shell, or any external command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Line 36 opens a fenced TypeScript example. The Markdown fence is not an executable backtick expression.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"Line 48 closes a fenced TypeScript example. It contains no command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Line 52 opens a documented Bash example for starting Node.js with an ESM loader. The skill does not execute the command automatically.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"Line 54 closes the ESM loader example's Markdown fence. It is not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Line 57 opens a fenced package configuration example. Markdown fencing cannot launch an external process.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"Line 63 closes a JSON example's Markdown fence. No command is executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"Line 67 opens a fenced TypeScript configuration example. The backticks are documentation syntax only.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"Line 103 closes a TypeScript code fence. It does not execute an external command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"Line 107 opens a fenced custom tracing example. It is static Markdown content, not a backtick execution expression.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"Line 126 closes a TypeScript code fence. No command execution behavior exists.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"Line 130 opens a fenced metrics example. The Markdown delimiter is not an execution primitive.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"Line 148 closes the metrics example's code fence. It cannot invoke Ruby or a shell.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"Line 154 opens a fenced TypeScript trace exporter example. The finding mistakes Markdown syntax for command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"Line 167 closes a TypeScript example. It has no executable backtick expression.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"Line 171 opens a fenced TypeScript metric exporter example. It is documentation rather than external command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"Line 185 closes a Markdown code fence. No command is launched.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"Line 189 opens a fenced TypeScript log exporter example. The static Markdown delimiter is not executable.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:202:ruby-shell-backtick-execution","reason":"Line 202 closes a TypeScript code fence. It does not execute a process.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"Line 206 opens a fenced TypeScript logs ingestion example. The Markdown fence itself performs no command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"Line 234 closes a TypeScript code fence. No external command primitive is present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"Line 238 opens a fenced TypeScript span processor example. It is inert documentation content.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:262:ruby-shell-backtick-execution","reason":"Line 262 closes the span processor example's Markdown fence. It cannot execute an external process.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"Line 266 opens a fenced TypeScript sampling example. The backticks are formatting syntax only.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","reason":"Line 274 closes a Markdown code fence. No command execution occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"Line 278 opens a fenced TypeScript shutdown example. It is not a Ruby or shell backtick expression.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:288:ruby-shell-backtick-execution","reason":"Line 288 closes the shutdown example's Markdown fence. It performs no command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:292:ruby-shell-backtick-execution","reason":"Line 292 opens a fenced TypeScript import reference. It is static documentation content.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"Line 312 closes a TypeScript code fence. It does not launch a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"Line 317 uses inline Markdown around an ESM loader argument. It is a documented command option, not backtick execution.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:210:hardcoded-url","reason":"The URL is a placeholder for the documented Azure Monitor ingestion endpoint. It contains no fixed tenant destination and matches the skill's stated telemetry purpose.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:41:environment-variable-access-dot-notation","reason":"The example reads only the named Application Insights connection string to configure its intended exporter. It does not enumerate, log, or transmit unrelated environment values.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:73:environment-variable-access-dot-notation","reason":"The full configuration example reads the expected Application Insights connection string. This is necessary exporter configuration, not broad environment access.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:159:environment-variable-access-dot-notation","reason":"The trace exporter example reads one explicitly named connection string for Azure Monitor. No unrelated secret access or disclosure is shown.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:177:environment-variable-access-dot-notation","reason":"The metric exporter example uses the expected named connection string. It does not inspect the environment object beyond that documented setting.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:195:environment-variable-access-dot-notation","reason":"The log exporter example reads the documented Application Insights connection string. This matches the declared observability function and reveals no value.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:41:environment-variable-object","reason":"The process.env reference targets one named exporter setting rather than enumerating the environment object. The example contains no credential collection logic.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:73:environment-variable-object","reason":"The process.env reference is limited to the documented Application Insights connection string. It is standard configuration access for this exporter.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:159:environment-variable-object","reason":"The trace exporter example accesses one known environment property. There is no environment enumeration or unauthorized destination.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:177:environment-variable-object","reason":"The metric exporter example accesses only its named Azure Monitor configuration value. This is expected behavior for the documented setup.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:195:environment-variable-object","reason":"The log exporter example references one specific environment property. It does not read or expose the complete environment object.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:41:environment-file-access","reason":"Line 41 reads a named process environment property and does not access an environment file. The connection string value is neither embedded nor printed.","verdict":"false_positive","confidence":1},{"id":"sensitive:SKILL.md:73:environment-file-access","reason":"Line 73 contains no file operation; it reads a named process environment property for exporter configuration. No secret value appears in the guide.","verdict":"false_positive","confidence":1},{"id":"sensitive:SKILL.md:159:environment-file-access","reason":"Line 159 does not read a file. It passes one named environment value to the documented Azure Monitor trace exporter.","verdict":"false_positive","confidence":1},{"id":"sensitive:SKILL.md:177:environment-file-access","reason":"Line 177 has no environment-file access. It references the standard connection string variable required by the metric exporter.","verdict":"false_positive","confidence":1},{"id":"sensitive:SKILL.md:195:environment-file-access","reason":"Line 195 reads one named process environment value and performs no filesystem operation. The example does not disclose the connection string.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:246:system-reconnaissance","reason":"onStart is an empty OpenTelemetry SpanProcessor lifecycle method. It performs no host, user, process, or network reconnaissance.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:248:system-reconnaissance","reason":"onEnd is an OpenTelemetry SpanProcessor callback that filters and enriches a completed span. It does not gather system information.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","subject_content_hash":"c4ff113940cc207dc0db8fd184fd236a3ae5c1bb782a4362eb0e8b350d8ce1cf","subject_tree_hash":"ee275fc8e68241736d77057440e60f257e3cd1857bf7fbcf2e53b403a7a7a926","subject_plugin_path":"skills/sickn33/azure-monitor-opentelemetry-ts","audit_payload_hash":"dd466fee20eefa1d98e2c355a5edee39","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","contentHash":"c4ff113940cc207dc0db8fd184fd236a3ae5c1bb782a4362eb0e8b350d8ce1cf","treeHash":"ee275fc8e68241736d77057440e60f257e3cd1857bf7fbcf2e53b403a7a7a926","pluginPath":"skills/sickn33/azure-monitor-opentelemetry-ts","auditPayloadHash":"dd466fee20eefa1d98e2c355a5edee39"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-azure-monitor-opentelemetry-ts/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}