{"data":{"skill":{"slug":"sickn33-hig-components-menus","name":"hig-components-menus","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/hig-components-menus","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"b446a729-a6bf-4b45-8e2a-97821cfa56d0","skill_id":"cb2a5e40-9c16-42d2-8416-167af660d585","version":5,"content_hash":"v3:88a8e9a07f4c54ab105c1c41b6267c287146b07b:3779a7bdb24ec0905100ced45289879d46c085e95350bfc483f637ee70353d33:8b092ff30a98ffcf4073854827d81197aaf5ddcc519c342133c74fb316f0b0df:736b696c6c732f7369636b6e33332f6869672d636f6d706f6e656e74732d6d656e7573:e6079ac15582039b0ba6371229ed3361","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 38 static findings are false positives. The 36 blocker alerts misclassify ordinary interface guidance, image text, or changelog text as reconnaissance; the remaining alerts are harmless Markdown.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":11,"line_start":11}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":74,"line_start":74}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":12,"total_lines":1610,"audit_model":"codex","audited_at":"2026-07-23T23:29:06.648+00:00","created_at":"2026-07-26T14:23:09.547852+00:00","static_findings":[{"id":"blocker:references/action-button.md:9:system-reconnaissance","file":"references/action-button.md","pattern":"System reconnaissance","snippet":"![A sketch of an arrow pointing toward the Action button on Apple Watch, suggesting initiating an ac","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:references/action-button.md:23:system-reconnaissance","file":"references/action-button.md","pattern":"System reconnaissance","snippet":"**Prefer letting the system show people how to use the Action button with your app.** When you suppo","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"blocker:references/buttons.md:40:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Avoid applying a similar color to button labels and content layer backgrounds.** If your app alrea","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"blocker:references/buttons.md:75:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Don’t assign the primary role to a button that performs a destructive action, even if that action ","category":"blocker","line_end":75,"severity":"low","line_start":75},{"id":"blocker:references/buttons.md:113:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Avoid using labels to introduce square buttons.** Because square buttons are closely connected wit","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/buttons.md:137:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Use a help button within a view, not in the window frame.** For example, avoid placing a help butt","category":"blocker","line_end":137,"severity":"low","line_start":137},{"id":"blocker:references/buttons.md:139:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Avoid displaying text that introduces a help button.** People know what a help button does, so the","category":"blocker","line_end":139,"severity":"low","line_start":139},{"id":"blocker:references/buttons.md:145:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Use an image button in a view, not in the window frame.** For example, avoid placing an image butt","category":"blocker","line_end":145,"severity":"low","line_start":145},{"id":"blocker:references/buttons.md:147:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Include about 10 pixels of padding between the edges of the image and the button edges.** An image","category":"blocker","line_end":147,"severity":"low","line_start":147},{"id":"blocker:references/buttons.md:203:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Avoid creating a custom button that uses a white background fill and black text or icons.** The sy","category":"blocker","line_end":203,"severity":"low","line_start":203},{"id":"blocker:references/buttons.md:207:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Provide enough space around a button to make it easy for people to look at it.** Aim to place butt","category":"blocker","line_end":207,"severity":"low","line_start":207},{"id":"blocker:references/buttons.md:219:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"**Use a toolbar to place buttons in the corners.** The system automatically moves the time and title","category":"blocker","line_end":219,"severity":"low","line_start":219},{"id":"blocker:references/buttons.md:255:system-reconnaissance","file":"references/buttons.md","pattern":"System reconnaissance","snippet":"December 16, 2025| Updated guidance for Liquid Glass.","category":"blocker","line_end":255,"severity":"low","line_start":255},{"id":"blocker:references/context-menus.md:76:system-reconnaissance","file":"references/context-menus.md","pattern":"System reconnaissance","snippet":"**In general, avoid letting a context menu’s height exceed the height of the window.** In visionOS, ","category":"blocker","line_end":76,"severity":"low","line_start":76},{"id":"blocker:references/edit-menus.md:34:system-reconnaissance","file":"references/edit-menus.md","pattern":"System reconnaissance","snippet":"**Offer commands that are relevant in the current context, removing or dimming commands that don’t a","category":"blocker","line_end":34,"severity":"low","line_start":34},{"id":"blocker:references/edit-menus.md:36:system-reconnaissance","file":"references/edit-menus.md","pattern":"System reconnaissance","snippet":"**List custom commands near relevant system-provided ones.** For example, if you offer custom format","category":"blocker","line_end":36,"severity":"low","line_start":36},{"id":"blocker:references/edit-menus.md:42:system-reconnaissance","file":"references/edit-menus.md","pattern":"System reconnaissance","snippet":"**In general, avoid implementing other controls that perform the same functions as edit menu items.*","category":"blocker","line_end":42,"severity":"low","line_start":42},{"id":"blocker:references/menus.md:39:system-reconnaissance","file":"references/menus.md","pattern":"System reconnaissance","snippet":"**Don’t display an icon if you can’t find one that clearly represents the menu item.** Not all menu ","category":"blocker","line_end":39,"severity":"low","line_start":39},{"id":"blocker:references/menus.md:89:system-reconnaissance","file":"references/menus.md","pattern":"System reconnaissance","snippet":"Menu items often represent attributes or objects that people can turn on or off. If you want to avoi","category":"blocker","line_end":89,"severity":"low","line_start":89},{"id":"blocker:references/pop-up-buttons.md:36:system-reconnaissance","file":"references/pop-up-buttons.md","pattern":"System reconnaissance","snippet":"**If necessary, include a Custom option in a pop-up button’s menu to provide additional items that a","category":"blocker","line_end":36,"severity":"low","line_start":36},{"id":"blocker:references/pull-down-buttons.md:28:system-reconnaissance","file":"references/pull-down-buttons.md","pattern":"System reconnaissance","snippet":"**Avoid putting all of a view’s actions in one pull-down button.** A view’s primary actions need to ","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:references/pull-down-buttons.md:34:system-reconnaissance","file":"references/pull-down-buttons.md","pattern":"System reconnaissance","snippet":"**Let people know when a pull-down button’s menu item is destructive, and ask them to confirm their ","category":"blocker","line_end":34,"severity":"low","line_start":34},{"id":"blocker:references/the-menu-bar.md:188:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"Zoom| Toggles between a predefined size appropriate to the window’s content and the window size peop","category":"blocker","line_end":188,"severity":"low","line_start":188},{"id":"blocker:references/the-menu-bar.md:195:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"_Name of an open app-specific window_|  Brings the selected window to the front.| List the currently","category":"blocker","line_end":195,"severity":"low","line_start":195},{"id":"blocker:references/the-menu-bar.md:205:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"_Additional Item_| |  Use a separator between your primary help documentation and additional items, ","category":"blocker","line_end":205,"severity":"low","line_start":205},{"id":"blocker:references/the-menu-bar.md:213:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"**Avoid making a dynamic menu item the only way to accomplish a task.** Dynamic menu items are hidde","category":"blocker","line_end":213,"severity":"low","line_start":213},{"id":"blocker:references/the-menu-bar.md:242:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"**Because the menu bar is often hidden when running an app full screen, ensure that people can acces","category":"blocker","line_end":242,"severity":"low","line_start":242},{"id":"blocker:references/the-menu-bar.md:262:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"When necessary, the system hides menu bar extras to make room for app menus. Similarly, if there are","category":"blocker","line_end":262,"severity":"low","line_start":262},{"id":"blocker:references/the-menu-bar.md:268:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"**Display a menu — not a popover — when people click your menu bar extra.** Unless the app functiona","category":"blocker","line_end":268,"severity":"low","line_start":268},{"id":"blocker:references/the-menu-bar.md:272:system-reconnaissance","file":"references/the-menu-bar.md","pattern":"System reconnaissance","snippet":"**Avoid relying on the presence of menu bar extras.** The system hides and shows menu bar extras reg","category":"blocker","line_end":272,"severity":"low","line_start":272},{"id":"blocker:references/toolbars.md:28:system-reconnaissance","file":"references/toolbars.md","pattern":"System reconnaissance","snippet":"**Choose items deliberately to avoid overcrowding.** People need to be able to distinguish and activ","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"blocker:references/toolbars.md:32:system-reconnaissance","file":"references/toolbars.md","pattern":"System reconnaissance","snippet":"The system automatically adds an overflow menu in macOS or iPadOS when items no longer fit. Don’t ad","category":"blocker","line_end":32,"severity":"low","line_start":32},{"id":"blocker:references/toolbars.md:49:system-reconnaissance","file":"references/toolbars.md","pattern":"System reconnaissance","snippet":"**Avoid applying a similar color to toolbar item labels and content layer backgrounds.** If your app","category":"blocker","line_end":49,"severity":"low","line_start":49},{"id":"blocker:references/toolbars.md:184:system-reconnaissance","file":"references/toolbars.md","pattern":"System reconnaissance","snippet":"**Avoid creating a vertical toolbar.** In visionOS, [tab bars](https://developer.apple.com/design/hu","category":"blocker","line_end":184,"severity":"low","line_start":184},{"id":"blocker:references/toolbars.md:190:system-reconnaissance","file":"references/toolbars.md","pattern":"System reconnaissance","snippet":"**Avoid using a pull-down menu in a toolbar.** A pull-down menu lets you offer additional actions re","category":"blocker","line_end":190,"severity":"low","line_start":190},{"id":"blocker:references/toolbars.md:252:system-reconnaissance","file":"references/toolbars.md","pattern":"System reconnaissance","snippet":"December 16, 2025| Updated guidance for Liquid Glass.","category":"blocker","line_end":252,"severity":"low","line_start":252},{"id":"external_commands:SKILL.md:11:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Check for `.claude/apple-design-context.md` before asking questions. Use existing context and only a","category":"external_commands","line_end":11,"severity":"medium","line_start":11},{"id":"network:SKILL.md:74:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"*Built by [Raintree Technology](https://raintree.technology) · [More developer tools](https://raintr","category":"network","line_end":74,"severity":"low","line_start":74}],"finding_verdicts":[{"id":"blocker:references/action-button.md:9:system-reconnaissance","reason":"The line is image alt text describing an Apple Watch Action button sketch, not an instruction to inspect a system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/action-button.md:23:system-reconnaissance","reason":"The word system refers to Apple-provided user guidance for the Action button and does not request host reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:40:system-reconnaissance","reason":"This is visual design advice about button label contrast and system colors, with no system inspection behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:75:system-reconnaissance","reason":"This line discusses assigning button roles to destructive actions and contains no reconnaissance instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:113:system-reconnaissance","reason":"This is interface guidance about labels for square buttons, not a request to discover system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:137:system-reconnaissance","reason":"This line recommends placing a help button within a view and does not direct any host inspection.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:139:system-reconnaissance","reason":"This line advises against explanatory text beside a familiar help button and has no security-relevant behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:145:system-reconnaissance","reason":"This is placement guidance for an image button in an application view, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:147:system-reconnaissance","reason":"This line specifies image-button padding and contains no instruction to inspect files, processes, or host configuration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:203:system-reconnaissance","reason":"This is visual styling guidance about custom buttons and system appearances, not a reconnaissance operation.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:207:system-reconnaissance","reason":"This line recommends adequate visual space around a button and has no system access intent.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:219:system-reconnaissance","reason":"The word system describes automatic Apple interface layout around toolbar buttons, not host discovery.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/buttons.md:255:system-reconnaissance","reason":"The line is a dated documentation changelog entry about Liquid Glass and contains no executable or investigative instruction.","verdict":"false_positive","confidence":1},{"id":"blocker:references/context-menus.md:76:system-reconnaissance","reason":"This line discusses context-menu height in visionOS and does not ask the agent to inspect a system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/edit-menus.md:34:system-reconnaissance","reason":"This is design guidance for enabling relevant edit commands based on application context, not host reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/edit-menus.md:36:system-reconnaissance","reason":"The line describes ordering custom commands near system-provided menu items and does not inspect the host.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/edit-menus.md:42:system-reconnaissance","reason":"This is user-interface advice about duplicate controls for edit actions, with no system discovery behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/menus.md:39:system-reconnaissance","reason":"This line advises omitting unclear menu icons and contains no reconnaissance or privileged operation.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/menus.md:89:system-reconnaissance","reason":"This line explains toggled menu items as interface state and does not request system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pop-up-buttons.md:36:system-reconnaissance","reason":"This is guidance for adding a Custom option to a pop-up button, not a host inspection instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pull-down-buttons.md:28:system-reconnaissance","reason":"This line warns against hiding every view action in one pull-down button and has no security-relevant behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pull-down-buttons.md:34:system-reconnaissance","reason":"This line recommends confirmation for destructive menu actions and does not direct system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:188:system-reconnaissance","reason":"This is a documentation table entry explaining the macOS Zoom command, not an instruction to inspect host settings.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:195:system-reconnaissance","reason":"This table row describes how a Window menu lists and activates open application windows, not host reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:205:system-reconnaissance","reason":"This documentation row explains Help menu item grouping and contains no investigative instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:213:system-reconnaissance","reason":"This is accessibility guidance about alternate access to dynamic menu commands, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:242:system-reconnaissance","reason":"The line discusses access to application commands when a menu bar is hidden in full screen, not host inspection.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:262:system-reconnaissance","reason":"The word system describes macOS hiding menu bar extras when space is limited and does not imply reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:268:system-reconnaissance","reason":"This is component-selection guidance for a menu bar extra and contains no host discovery behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/the-menu-bar.md:272:system-reconnaissance","reason":"This line explains that macOS may hide menu bar extras and does not instruct the agent to inspect a system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/toolbars.md:28:system-reconnaissance","reason":"This is toolbar organization guidance intended to prevent overcrowding, with no system access or inspection.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/toolbars.md:32:system-reconnaissance","reason":"The word system refers to automatic overflow-menu behavior in macOS and iPadOS, not reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/toolbars.md:49:system-reconnaissance","reason":"This is visual contrast guidance for toolbar labels and backgrounds, not an instruction to inspect host data.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/toolbars.md:184:system-reconnaissance","reason":"This line recommends against vertical toolbars in visionOS and links related interface guidance without requesting reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/toolbars.md:190:system-reconnaissance","reason":"This line advises against pull-down menus in toolbars and contains no security-sensitive instruction.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/toolbars.md:252:system-reconnaissance","reason":"The line is a dated documentation changelog entry about Liquid Glass and contains no executable or investigative instruction.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:11:ruby-shell-backtick-execution","reason":"The backticks delimit the literal Markdown path .claude/apple-design-context.md; they do not execute Ruby or shell commands.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:74:hardcoded-url","reason":"The hardcoded HTTPS URLs are attribution and related-tools links in Markdown, with no instruction or code that makes a network request.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","subject_content_hash":"3779a7bdb24ec0905100ced45289879d46c085e95350bfc483f637ee70353d33","subject_tree_hash":"8b092ff30a98ffcf4073854827d81197aaf5ddcc519c342133c74fb316f0b0df","subject_plugin_path":"skills/sickn33/hig-components-menus","audit_payload_hash":"e6079ac15582039b0ba6371229ed3361","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","contentHash":"3779a7bdb24ec0905100ced45289879d46c085e95350bfc483f637ee70353d33","treeHash":"8b092ff30a98ffcf4073854827d81197aaf5ddcc519c342133c74fb316f0b0df","pluginPath":"skills/sickn33/hig-components-menus","auditPayloadHash":"e6079ac15582039b0ba6371229ed3361"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-hig-components-menus/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}