{"data":{"skill":{"slug":"sickn33-internal-comms","name":"internal-comms","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/web-app/public/skills/internal-comms-community","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"a60b836e-7758-4503-83cd-d7f3e9ef0b14","skill_id":"f887ed12-911f-40a5-a424-b9660524128a","version":4,"content_hash":"v3:816c62b2546ddb1c6a0453e7c781b5e095117819:067b7587a344a928fc6534ef66b1bcd591fc7c26d207ea7ca3334aeb678d6475:a6b5345233ee5a870ded83fcd454c1d34135f5e654b4260bfa18b4799e632e91:736b696c6c732f7369636b6e33332f696e7465726e616c2d636f6d6d73:26c2258821ef3a62ec86ea17764115c9","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The static analyzer flagged Markdown inline-code file references in SKILL.md lines 22-26 as shell backtick execution. Those lines are prose references to guideline filenames, not executable commands. Review found no prompt injection or malicious intent in SKILL.md.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":26,"line_start":26}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":235,"audit_model":"codex","audited_at":"2026-07-07T01:23:33.474+00:00","created_at":"2026-07-17T20:00:06.239239+00:00","static_findings":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Load the appropriate guideline file** from the `examples/` directory:","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/3p-updates.md` - For Progress/Plans/Problems team updates","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/company-newsletter.md` - For company-wide newsletters","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/faq-answers.md` - For answering frequently asked questions","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `examples/general-comms.md` - For anything else that doesn't explicitly match one of the above","category":"external_commands","line_end":26,"severity":"medium","line_start":26}],"finding_verdicts":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"Line 22 is Markdown prose that uses inline backticks around the examples directory name. It contains no Ruby, shell command, or executable instruction.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"Line 23 is a Markdown bullet naming examples/3p-updates.md as a guideline file. The backticks mark a filename, not command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"Line 24 is a Markdown bullet naming examples/company-newsletter.md as a guideline file. The backticks mark a filename, not command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"Line 25 is a Markdown bullet naming examples/faq-answers.md as a guideline file. The backticks mark a filename, not command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Line 26 is a Markdown bullet naming examples/general-comms.md as a guideline file. The backticks mark a filename, not command execution.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[],"subject_marketplace_commit_sha":"816c62b2546ddb1c6a0453e7c781b5e095117819","subject_content_hash":"067b7587a344a928fc6534ef66b1bcd591fc7c26d207ea7ca3334aeb678d6475","subject_tree_hash":"a6b5345233ee5a870ded83fcd454c1d34135f5e654b4260bfa18b4799e632e91","subject_plugin_path":"skills/sickn33/internal-comms","audit_payload_hash":"26c2258821ef3a62ec86ea17764115c9","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"816c62b2546ddb1c6a0453e7c781b5e095117819","contentHash":"067b7587a344a928fc6534ef66b1bcd591fc7c26d207ea7ca3334aeb678d6475","treeHash":"a6b5345233ee5a870ded83fcd454c1d34135f5e654b4260bfa18b4799e632e91","pluginPath":"skills/sickn33/internal-comms","auditPayloadHash":"26c2258821ef3a62ec86ea17764115c9"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}