{"data":{"skill":{"slug":"sickn33-design-orchestration","name":"design-orchestration","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/design-orchestration","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"9cd835ce-e5f2-4813-bb50-404e8aaea765","skill_id":"07b1759d-ce83-4ed4-9e12-2bdf344a50fb","version":5,"content_hash":"v3:f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526:b953414d388f30a80f3ce7e865d2cdb943dcdd5062699ac814e5401b0ed68ab4:fc24614b39dc4445cb1a5b79199b7b1065abf31be131dc206721c4a92b5d54c2:736b696c6c732f7369636b6e33332f64657369676e2d6f726368657374726174696f6e:9fd08ee7edd0416232d405f4ec675104","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All six static findings are false positives caused by Markdown backticks around companion skill names, not executable shell syntax. The reviewed file contains no commands, scripts, network activity, secret access, or prompt injection.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":91,"line_start":91},{"file":"SKILL.md","line_end":94,"line_start":94},{"file":"SKILL.md","line_end":102,"line_start":102}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":175,"audit_model":"codex","audited_at":"2026-07-23T22:09:39.449+00:00","created_at":"2026-07-26T09:23:07.06068+00:00","static_findings":[{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `brainstorming` — design generation","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `multi-agent-brainstorming` — design validation","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Invoke `brainstorming`","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"→ Recommend `multi-agent-brainstorming`","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"→ REQUIRE `multi-agent-brainstorming`","category":"external_commands","line_end":94,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If `multi-agent-brainstorming` is run:","category":"external_commands","line_end":102,"severity":"medium","line_start":102}],"finding_verdicts":[{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Line 36 uses Markdown backticks to format the companion skill name `brainstorming` in a list and contains no executable command syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"Line 37 uses Markdown backticks to format the companion skill name `multi-agent-brainstorming` in a list and contains no executable command syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Line 57 instructs workflow routing to the `brainstorming` skill, with backticks serving only as Markdown formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"Line 91 recommends a named companion skill in prose and does not invoke a shell, interpreter, or external process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"Line 94 requires a named review skill as a workflow step, while its backticks are Markdown delimiters rather than execution operators.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"Line 102 conditionally references a companion skill in prose and provides no command, arguments, or execution mechanism.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","subject_content_hash":"b953414d388f30a80f3ce7e865d2cdb943dcdd5062699ac814e5401b0ed68ab4","subject_tree_hash":"fc24614b39dc4445cb1a5b79199b7b1065abf31be131dc206721c4a92b5d54c2","subject_plugin_path":"skills/sickn33/design-orchestration","audit_payload_hash":"9fd08ee7edd0416232d405f4ec675104","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","contentHash":"b953414d388f30a80f3ce7e865d2cdb943dcdd5062699ac814e5401b0ed68ab4","treeHash":"fc24614b39dc4445cb1a5b79199b7b1065abf31be131dc206721c4a92b5d54c2","pluginPath":"skills/sickn33/design-orchestration","auditPayloadHash":"9fd08ee7edd0416232d405f4ec675104"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-design-orchestration/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}