{"data":{"skill":{"slug":"sickn33-finishing-a-development-branch","name":"finishing-a-development-branch","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/finishing-a-development-branch","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"2ba24d38-ce53-40bd-8477-c91f058ee384","skill_id":"397e0038-efe8-4482-b622-734e82e3a6c7","version":5,"content_hash":"v3:88a8e9a07f4c54ab105c1c41b6267c287146b07b:9ea0cfe6ec834aab44a063d37028b9ba13174573981bae481829df8a4e591e24:437d6172203b0e5577fcaea749256b990186bd5dcd0945f95ba53a8c64e25fd9:736b696c6c732f7369636b6e33332f66696e697368696e672d612d646576656c6f706d656e742d6272616e6368:c9068c9fa27322ad4cadb3f51533eea4","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 24 static findings are false positives. Most detections are Markdown code-fence delimiters, while the shell substitutions compose fixed text or query local Git state without reevaluating output as shell code. Standard error redirection to /dev/null is benign, and destructive cleanup requires an explicit workflow choice and typed confirmation.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":28,"line_start":25},{"file":"SKILL.md","line_end":31,"line_start":28},{"file":"SKILL.md","line_end":37,"line_start":31},{"file":"SKILL.md","line_end":45,"line_start":37},{"file":"SKILL.md","line_end":48,"line_start":45},{"file":"SKILL.md","line_end":56,"line_start":48},{"file":"SKILL.md","line_end":65,"line_start":56},{"file":"SKILL.md","line_end":73,"line_start":65},{"file":"SKILL.md","line_end":88,"line_start":73},{"file":"SKILL.md","line_end":94,"line_start":88},{"file":"SKILL.md","line_end":107,"line_start":94},{"file":"SKILL.md","line_end":120,"line_start":107},{"file":"SKILL.md","line_end":127,"line_start":120},{"file":"SKILL.md","line_end":132,"line_start":127},{"file":"SKILL.md","line_end":135,"line_start":132},{"file":"SKILL.md","line_end":144,"line_start":135},{"file":"SKILL.md","line_end":146,"line_start":144},{"file":"SKILL.md","line_end":149,"line_start":146},{"file":"SKILL.md","line_end":151,"line_start":149},{"file":"SKILL.md","line_end":106,"line_start":99},{"file":"SKILL.md","line_end":145,"line_start":145},{"file":"SKILL.md","line_end":107,"line_start":94},{"file":"SKILL.md","line_end":146,"line_start":144}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":47,"line_start":47}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":212,"audit_model":"codex","audited_at":"2026-07-23T22:13:26.297+00:00","created_at":"2026-07-26T12:22:01.115016+00:00","static_findings":[{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":28,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":31,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":37,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":45,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":48,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":56,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":73,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":88,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":94,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":107,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":120,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":127,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":132,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":135,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":144,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":146,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":149,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":151,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:99:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"gh pr create --title \"<title>\" --body \"$(cat <<'EOF'","category":"external_commands","line_end":106,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:145:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"git worktree list | grep $(git branch --show-current)","category":"external_commands","line_end":145,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:94:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":107,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:144:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":146,"severity":"medium","line_start":144},{"id":"filesystem:SKILL.md:47:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"git merge-base HEAD main 2>/dev/null || git merge-base HEAD master 2>/dev/null","category":"filesystem","line_end":47,"severity":"low","line_start":47}],"finding_verdicts":[{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The matched text is the opening Markdown fence for a Bash example. It is documentation syntax, not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The matched text is a closing Markdown code fence. It does not invoke a command or evaluate content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The matched triple backticks open a plain-text example of test failure output. They are Markdown delimiters, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The finding points to a Markdown fence closing a displayed message. No shell or Ruby execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"The snippet is an opening Bash code fence used to document base-branch detection. The fence itself has no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The snippet is a closing Markdown code fence. Static analysis has mistaken formatting backticks for executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The triple backticks delimit a displayed list of workflow choices. They do not execute the list as a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The matched text closes a Markdown example block. It contains no executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The matched token opens a documented Bash workflow. It is a Markdown fence rather than a Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The token is the closing fence for the local merge example. Markdown delimiters do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"The snippet is an opening Bash code fence for the pull request example. It is documentation syntax, not backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The matched text closes the pull request command example. It cannot execute the preceding content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The triple backticks open a plain-text confirmation message. The block is user-facing documentation and contains no executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The matched token closes the documented discard confirmation. It is not interpreted as shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The snippet opens a Bash example shown only after exact discard confirmation. The finding concerns the Markdown delimiter, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"The matched triple backticks close the confirmed discard example. They are formatting syntax only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The token opens a Bash example for checking worktree membership. It is a Markdown fence, not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The matched token is the closing Markdown fence for the worktree check. It has no command execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The snippet opens a documented Bash example for user-selected cleanup. The fence itself does not execute the command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:shell-command-substitution","reason":"The command substitution captures a fixed, single-quoted heredoc to form the pull request body. It does not evaluate repository or user content as shell code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:145:shell-command-substitution","reason":"The substitution reads the current local Git branch for a worktree check. Shell substitution output is passed to grep and is not reevaluated as executable shell syntax.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:SKILL.md:94:template-literal-with-command-substitution","reason":"The matched snippet is a Markdown Bash fence, not a programming-language template literal. The analyzer has classified documentation formatting as executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:template-literal-with-command-substitution","reason":"The triple backticks start a Markdown Bash block. No template literal or embedded command expression exists in the matched token.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:47:standard-device-file-access","reason":"The command redirects expected merge-base errors to /dev/null. This standard device access only discards stderr and does not read, alter, or expose user files.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","subject_content_hash":"9ea0cfe6ec834aab44a063d37028b9ba13174573981bae481829df8a4e591e24","subject_tree_hash":"437d6172203b0e5577fcaea749256b990186bd5dcd0945f95ba53a8c64e25fd9","subject_plugin_path":"skills/sickn33/finishing-a-development-branch","audit_payload_hash":"c9068c9fa27322ad4cadb3f51533eea4","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","contentHash":"9ea0cfe6ec834aab44a063d37028b9ba13174573981bae481829df8a4e591e24","treeHash":"437d6172203b0e5577fcaea749256b990186bd5dcd0945f95ba53a8c64e25fd9","pluginPath":"skills/sickn33/finishing-a-development-branch","auditPayloadHash":"c9068c9fa27322ad4cadb3f51533eea4"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-finishing-a-development-branch/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}