{"data":{"skill":{"slug":"sickn33-azure-monitor-query-py","name":"azure-monitor-query-py","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/azure-monitor-query-py","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"447fbffa-c52a-4554-a8c3-3feb31f6ff44","skill_id":"e88930e8-ac83-4c1f-9c7d-625552b67679","version":5,"content_hash":"v3:f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526:68941a2a06b622a878c6f0aee1f8f8b2b04ec25480e5d334694895d45371ef7c:1ec3187da37a2c9512fd92a554020a229460bcaa0d353fdf31e24e6347e4aaf5:736b696c6c732f7369636b6e33332f617a7572652d6d6f6e69746f722d71756572792d7079:28a244c50eb119a8098a22cea70383a3","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The 31 external-command alerts are false positives caused by Markdown fences and inline code formatting; none performs Ruby or shell backtick execution. The two environment reads retrieve documented Azure resource identifiers for intended SDK calls, with no credential disclosure or unrelated transmission. No prompt injection or other semantic security issue was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":17,"line_start":15},{"file":"SKILL.md","line_end":21,"line_start":17},{"file":"SKILL.md","line_end":27,"line_start":21},{"file":"SKILL.md","line_end":31,"line_start":27},{"file":"SKILL.md","line_end":35,"line_start":31},{"file":"SKILL.md","line_end":41,"line_start":35},{"file":"SKILL.md","line_end":63,"line_start":41},{"file":"SKILL.md","line_end":67,"line_start":63},{"file":"SKILL.md","line_end":78,"line_start":67},{"file":"SKILL.md","line_end":82,"line_start":78},{"file":"SKILL.md","line_end":91,"line_start":82},{"file":"SKILL.md","line_end":95,"line_start":91},{"file":"SKILL.md","line_end":108,"line_start":95},{"file":"SKILL.md","line_end":112,"line_start":108},{"file":"SKILL.md","line_end":121,"line_start":112},{"file":"SKILL.md","line_end":127,"line_start":121},{"file":"SKILL.md","line_end":145,"line_start":127},{"file":"SKILL.md","line_end":149,"line_start":145},{"file":"SKILL.md","line_end":163,"line_start":149},{"file":"SKILL.md","line_end":167,"line_start":163},{"file":"SKILL.md","line_end":174,"line_start":167},{"file":"SKILL.md","line_end":178,"line_start":174},{"file":"SKILL.md","line_end":182,"line_start":178},{"file":"SKILL.md","line_end":186,"line_start":182},{"file":"SKILL.md","line_end":190,"line_start":186},{"file":"SKILL.md","line_end":194,"line_start":190},{"file":"SKILL.md","line_end":211,"line_start":194},{"file":"SKILL.md","line_end":215,"line_start":211},{"file":"SKILL.md","line_end":235,"line_start":215},{"file":"SKILL.md","line_end":241,"line_start":235},{"file":"SKILL.md","line_end":242,"line_start":241}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":134,"line_start":134}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":261,"audit_model":"codex","audited_at":"2026-07-23T22:08:59.424+00:00","created_at":"2026-07-26T06:21:01.81826+00:00","static_findings":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":17,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":21,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":27,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":31,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":35,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":41,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":63,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":67,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":78,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":82,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":91,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":95,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":108,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":112,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":121,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":127,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":145,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":149,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":163,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":167,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":174,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":178,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":182,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":186,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":190,"severity":"medium","line_start":186},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":194,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":211,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":215,"severity":"medium","line_start":211},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```kusto","category":"external_commands","line_end":235,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":241,"severity":"medium","line_start":235},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `LogsQueryClient` | Query Log Analytics workspaces |","category":"external_commands","line_end":242,"severity":"medium","line_start":241},{"id":"env_access:SKILL.md:55:python-environment-access","file":"SKILL.md","pattern":"Python environment access","snippet":"workspace_id=os.environ[\"AZURE_LOG_ANALYTICS_WORKSPACE_ID\"],","category":"env_access","line_end":55,"severity":"low","line_start":55},{"id":"env_access:SKILL.md:134:python-environment-access","file":"SKILL.md","pattern":"Python environment access","snippet":"resource_uri=os.environ[\"AZURE_METRICS_RESOURCE_URI\"],","category":"env_access","line_end":134,"severity":"low","line_start":134}],"finding_verdicts":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"Line 15 is a Markdown fence that opens a documented Bash installation example. It is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"Line 17 is the closing Markdown fence for the installation example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"Line 21 is a Markdown fence that opens a Bash-formatted environment configuration example. It does not invoke a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Line 27 is the closing Markdown fence for environment variable examples. It has no execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Line 31 is a Markdown fence that opens a Python authentication example. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"Line 35 closes a Markdown Python block. It does not run Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"Line 41 is a Markdown fence for a Python log query example. The backticks only control documentation formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"Line 63 closes the Python log query block. It contains no command execution mechanism.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"Line 67 opens a Markdown Python block for a time-range query example. It is inert documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"Line 78 closes the time-range Python example. It does not execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"Line 82 opens a Markdown Python block for DataFrame conversion. The backticks are formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"Line 91 closes the DataFrame example block. It has no command execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"Line 95 opens a Markdown Python block for an Azure SDK batch query. It does not invoke an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"Line 108 closes the batch query example. The detected backticks are inert Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"Line 112 opens a Markdown Python block about partial results. It is not dynamic code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"Line 121 closes the partial-results example. It does not run a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"Line 127 opens a Markdown Python block for a metrics query. The backticks only delimit sample code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"Line 145 closes the metrics query example. It has no Ruby or shell execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"Line 149 opens a Markdown Python block for metric aggregations. It is documentation syntax, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"Line 163 closes the metric aggregation example. The backticks are not evaluated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"Line 167 opens a Markdown Python block for a metric dimension filter. It does not execute external code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"Line 174 closes the dimension filter example. It is inert Markdown formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"Line 178 opens a Markdown Python block for listing metric definitions. It is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"Line 182 closes the metric definitions example. It has no execution effect.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:186:ruby-shell-backtick-execution","reason":"Line 186 opens a Markdown Python block for listing metric namespaces. The fence does not invoke a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"Line 190 closes the metric namespaces example. It is formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"Line 194 opens a Markdown Python block for asynchronous Azure clients. It is not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:211:ruby-shell-backtick-execution","reason":"Line 211 closes the asynchronous client example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","reason":"Line 215 opens a Markdown Kusto block containing query examples. It is not shell backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:235:ruby-shell-backtick-execution","reason":"Line 235 closes the Kusto query block. It has no command execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"Line 241 uses inline Markdown backticks to format the LogsQueryClient name in a table. It does not execute Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:55:python-environment-access","reason":"The example reads a documented Log Analytics workspace identifier and passes it to the intended Azure SDK method. It does not access credentials or disclose the value.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:134:python-environment-access","reason":"The example reads a documented Azure resource URI for the intended metrics query. The identifier is not exposed or transmitted to an unrelated destination.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[],"subject_marketplace_commit_sha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","subject_content_hash":"68941a2a06b622a878c6f0aee1f8f8b2b04ec25480e5d334694895d45371ef7c","subject_tree_hash":"1ec3187da37a2c9512fd92a554020a229460bcaa0d353fdf31e24e6347e4aaf5","subject_plugin_path":"skills/sickn33/azure-monitor-query-py","audit_payload_hash":"28a244c50eb119a8098a22cea70383a3","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","contentHash":"68941a2a06b622a878c6f0aee1f8f8b2b04ec25480e5d334694895d45371ef7c","treeHash":"1ec3187da37a2c9512fd92a554020a229460bcaa0d353fdf31e24e6347e4aaf5","pluginPath":"skills/sickn33/azure-monitor-query-py","auditPayloadHash":"28a244c50eb119a8098a22cea70383a3"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-azure-monitor-query-py/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}