{"data":{"skill":{"slug":"sickn33-bazel-build-optimization","name":"bazel-build-optimization","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/bazel-build-optimization","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"c51cbe09-88a1-4801-9363-ac7172a889fb","skill_id":"d86e2cc1-2ee6-41bf-b9b2-6a4fd7bc8ef8","version":5,"content_hash":"v3:5a26d1d61d694db29af9b138c661c1981076d9df:7d033a761f7b55e3fff080b96687f173449d63906d8856e1282763fbe5cfe9f2:6e4b70c7e4730f2ac9940c1b7012eb0a646eb3f2736bf693e36e6541950aa73b:736b696c6c732f7369636b6e33332f62617a656c2d6275696c642d6f7074696d697a6174696f6e:adf7132466a939060dac83673ee41d74","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 32 static findings are false positives caused by Markdown formatting, examples, trusted documentation links, cache paths, and a Bazel mnemonic. One medium semantic risk remains: the remote execution template uses a mutable latest container tag, which can change without review.","remediation":[{"issue":"The remote execution example references a container image with the mutable latest tag.","severity":"medium","suggestion":"Pin the worker image by immutable digest and document a controlled process for reviewing and updating that digest."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":53,"line_start":38},{"file":"SKILL.md","line_end":61,"line_start":53},{"file":"SKILL.md","line_end":69,"line_start":61},{"file":"SKILL.md","line_end":112,"line_start":69},{"file":"SKILL.md","line_end":116,"line_start":112},{"file":"SKILL.md","line_end":167,"line_start":116},{"file":"SKILL.md","line_end":171,"line_start":167},{"file":"SKILL.md","line_end":208,"line_start":171},{"file":"SKILL.md","line_end":212,"line_start":208},{"file":"SKILL.md","line_end":246,"line_start":212},{"file":"SKILL.md","line_end":250,"line_start":246},{"file":"SKILL.md","line_end":293,"line_start":250},{"file":"SKILL.md","line_end":297,"line_start":293},{"file":"SKILL.md","line_end":321,"line_start":297},{"file":"SKILL.md","line_end":325,"line_start":321},{"file":"SKILL.md","line_end":362,"line_start":325},{"file":"SKILL.md","line_end":366,"line_start":362},{"file":"SKILL.md","line_end":379,"line_start":366},{"file":"SKILL.md","line_end":308,"line_start":308},{"file":"SKILL.md","line_end":321,"line_start":297}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":150,"line_start":150},{"file":"SKILL.md","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":399,"line_start":399},{"file":"SKILL.md","line_end":400,"line_start":400}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":131,"line_start":131},{"file":"SKILL.md","line_end":130,"line_start":130},{"file":"SKILL.md","line_end":131,"line_start":131}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Mutable Remote Worker Image","locations":[{"file":"SKILL.md","line_end":334,"line_start":334}],"confidence":0.94,"description":"The remote execution example uses a latest container tag, allowing worker contents to change without an auditable configuration update.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Line 334 explicitly configures a remote execution container with the mutable latest tag. Pinning a digest is the established integrity control."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":406,"audit_model":"codex","audited_at":"2026-08-14T10:18:09.157+00:00","created_at":"2026-08-15T04:56:21.82175+00:00","static_findings":[{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If detailed examples are required, open `resources/implementation-playbook.md`.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":61,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Label** | Target identifier `//path/to:target` |","category":"external_commands","line_end":69,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":112,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":116,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":167,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":171,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":208,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":212,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":246,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":250,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":293,"severity":"medium","line_start":250},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":297,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":321,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":325,"severity":"medium","line_start":321},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":362,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":366,"severity":"medium","line_start":362},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":379,"severity":"medium","line_start":366},{"id":"external_commands:SKILL.md:308:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"bazel query \"rdeps(//..., set($(git diff --name-only HEAD~1 | sed 's/.*/\"&\"/' | tr '\\n' ' ')))\"","category":"external_commands","line_end":308,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:297:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":321,"severity":"medium","line_start":297},{"id":"network:SKILL.md:80:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"url = \"https://github.com/aspect-build/rules_js/releases/download/v1.34.0/rules_js-v1.34.0.tar.gz\",","category":"network","line_end":80,"severity":"low","line_start":80},{"id":"network:SKILL.md:107:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"url = \"https://github.com/bazelbuild/rules_python/releases/download/0.27.0/rules_python-0.27.0.tar.g","category":"network","line_end":107,"severity":"low","line_start":107},{"id":"network:SKILL.md:150:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"build:ci --bes_results_url=https://results.example.com/invocation/","category":"network","line_end":150,"severity":"low","line_start":150},{"id":"network:SKILL.md:398:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Bazel Documentation](https://bazel.build/docs)","category":"network","line_end":398,"severity":"low","line_start":398},{"id":"network:SKILL.md:399:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Bazel Remote Execution](https://bazel.build/docs/remote-execution)","category":"network","line_end":399,"severity":"low","line_start":399},{"id":"network:SKILL.md:400:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [rules_js](https://github.com/aspect-build/rules_js)","category":"network","line_end":400,"severity":"low","line_start":400},{"id":"filesystem:SKILL.md:130:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"build --disk_cache=~/.cache/bazel-disk","category":"filesystem","line_end":130,"severity":"high","line_start":130},{"id":"filesystem:SKILL.md:131:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"build --repository_cache=~/.cache/bazel-repo","category":"filesystem","line_end":131,"severity":"high","line_start":131},{"id":"filesystem:SKILL.md:130:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"build --disk_cache=~/.cache/bazel-disk","category":"filesystem","line_end":130,"severity":"medium","line_start":130},{"id":"filesystem:SKILL.md:131:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"build --repository_cache=~/.cache/bazel-repo","category":"filesystem","line_end":131,"severity":"medium","line_start":131},{"id":"sensitive:SKILL.md:271:crypto-seed-private-key-mention","file":"SKILL.md","pattern":"Crypto seed/private key mention","snippet":"mnemonic = \"DockerBuild\",","category":"sensitive","line_end":271,"severity":"high","line_start":271}],"finding_verdicts":[{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"Line 23 uses Markdown backticks around a resource path. It does not execute Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The backticks open a Markdown code fence containing a directory tree. No executable construct is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"Line 53 closes the Markdown directory-tree fence. It does not invoke a command interpreter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"Line 61 formats a Bazel label as inline Markdown code. The label is explanatory text, not executable input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The fence contains a declarative Bazel WORKSPACE example. Markdown backticks are not Ruby shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"Line 112 only closes a Markdown example. It contains no command or dynamic execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The bash fence labels a static .bazelrc configuration example. The backticks themselves execute nothing.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"Line 167 closes the .bazelrc Markdown fence. No Ruby or shell backtick expression exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"The fence contains a declarative TypeScript BUILD target example. It does not use backticks for command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"Line 208 is a Markdown fence terminator. It cannot execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The fenced content is declarative Starlark for Python targets. Markdown formatting caused the detection.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"Line 246 only closes a Markdown code sample. There is no shell evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:250:ruby-shell-backtick-execution","reason":"The fence contains a Bazel custom-rule example. Its Starlark action is explicit and does not use shell backtick evaluation.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"Line 293 closes the Starlark example. The Markdown delimiter is not executable.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"Line 297 opens a Markdown bash example. Triple backticks do not represent Ruby shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:321:ruby-shell-backtick-execution","reason":"Line 321 terminates a Markdown command example. It is not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"The fenced block is declarative Bazel platform and toolchain configuration. Markdown backticks caused the match.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","reason":"Line 362 closes a Markdown Starlark example. No external command is executed by this text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","reason":"Line 366 opens a Markdown block of fixed Bazel profiling commands. It is not Ruby backtick execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:308:shell-command-substitution","reason":"The documented pipeline uses fixed Git, sed, tr, and Bazel commands. Substitution remains inside one quoted query argument without eval or secret handling.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:297:template-literal-with-command-substitution","reason":"The detected range is a Markdown bash fence, not a JavaScript template literal. Its command substitution is separately visible and uses fixed local tools.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:80:hardcoded-url","reason":"The URL identifies a versioned rules_js release on its official GitHub repository. It is a transparent dependency source, not an exfiltration endpoint.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:107:hardcoded-url","reason":"The URL identifies a versioned rules_python release on the official Bazel GitHub organization. No credentials or local data are transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:150:hardcoded-url","reason":"The example.com address is an obvious placeholder for a user-controlled build results service. It does not direct data to an author-controlled endpoint.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:398:hardcoded-url","reason":"This is a Markdown link to official Bazel documentation. Merely presenting a documentation link is not risky network behavior.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:399:hardcoded-url","reason":"This is an official Bazel documentation link for remote execution. It neither sends local data nor triggers a request automatically.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:400:hardcoded-url","reason":"This Markdown resource link points to the public rules_js repository. It is informational and does not perform a network action.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:130:hidden-file-in-home-directory","reason":"The path is a conventional Bazel disk cache under the user cache directory. It does not target credentials or sensitive configuration.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:131:hidden-file-in-home-directory","reason":"The path stores Bazel repository cache data under the standard user cache directory. It is not a sensitive hidden file.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:130:hidden-file-access","reason":"This .bazelrc option selects a local build cache directory. The example does not read unrelated hidden files.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:131:hidden-file-access","reason":"This option selects a repository cache location under ~/.cache. Its scope is build artifacts, not private user data.","verdict":"false_positive","confidence":0.97},{"id":"sensitive:SKILL.md:271:crypto-seed-private-key-mention","reason":"DockerBuild is a Bazel action mnemonic used for logging. It is unrelated to cryptocurrency seed phrases or private keys.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Mutable Remote Worker Image","severity":"medium","locations":[{"file":"SKILL.md","line_end":334,"line_start":334}],"confidence":0.94,"description":"The remote execution example uses a latest container tag, allowing worker contents to change without an auditable configuration update.","confidence_reasoning":"Line 334 explicitly configures a remote execution container with the mutable latest tag. Pinning a digest is the established integrity control."}],"subject_marketplace_commit_sha":"5a26d1d61d694db29af9b138c661c1981076d9df","subject_content_hash":"7d033a761f7b55e3fff080b96687f173449d63906d8856e1282763fbe5cfe9f2","subject_tree_hash":"6e4b70c7e4730f2ac9940c1b7012eb0a646eb3f2736bf693e36e6541950aa73b","subject_plugin_path":"skills/sickn33/bazel-build-optimization","audit_payload_hash":"adf7132466a939060dac83673ee41d74","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"5a26d1d61d694db29af9b138c661c1981076d9df","contentHash":"7d033a761f7b55e3fff080b96687f173449d63906d8856e1282763fbe5cfe9f2","treeHash":"6e4b70c7e4730f2ac9940c1b7012eb0a646eb3f2736bf693e36e6541950aa73b","pluginPath":"skills/sickn33/bazel-build-optimization","auditPayloadHash":"adf7132466a939060dac83673ee41d74"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-bazel-build-optimization/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}