{"data":{"skill":{"slug":"sickn33-memory-systems","name":"memory-systems","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/memory-systems","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"84a9f2e3-42a9-4671-a7b1-b9f0100adab7","skill_id":"c99910d6-4e7a-41b2-b96a-a46bc067bc44","version":4,"content_hash":"v3:816c62b2546ddb1c6a0453e7c781b5e095117819:08acc6bd472ff178c40251591cb02155a3c6b50fbbeefe39b34f7eb99cf9c549:133891558dd36b26ec6856c555cb2efcee4ae20816e8133223de71bc1181da1c:736b696c6c732f7369636b6e33332f6d656d6f72792d73797374656d73:28b32055ad5e7bc6b61f5da011206e37","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The static findings are false positives caused by Markdown code fences, source metadata, and benign memory-system examples. I found no prompt injection, malicious intent, command execution behavior, or unauthorized network behavior in SKILL.md.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":173,"line_start":161},{"file":"SKILL.md","line_end":176,"line_start":173},{"file":"SKILL.md","line_end":186,"line_start":176}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":229,"audit_model":"codex","audited_at":"2026-07-07T00:22:44.798+00:00","created_at":"2026-07-17T20:10:11.65136+00:00","static_findings":[{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":173,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":176,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":186,"severity":"medium","line_start":176},{"id":"network:SKILL.md:4:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"source: \"https://github.com/muratcankoylan/Agent-Skills-for-Context-Engineering/tree/main/skills/mem","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"blocker:SKILL.md:45:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Vector stores lose relationship information. If an agent learns that \"Customer X purchased Product Y","category":"blocker","line_end":45,"severity":"low","line_start":45},{"id":"blocker:SKILL.md:52:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Temporal knowledge graphs add validity periods to facts. Each fact has a \"valid from\" and optionally","category":"blocker","line_end":52,"severity":"low","line_start":52},{"id":"blocker:SKILL.md:100:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"This enables queries like \"What was the user's address on Date X?\" by retrieving facts valid during ","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:SKILL.md:132:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Retrieve memories valid at specific time or within time range using validity period filters.","category":"blocker","line_end":132,"severity":"low","line_start":132},{"id":"blocker:SKILL.md:181:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"WHERE user.id = $user_id","category":"blocker","line_end":181,"severity":"low","line_start":181}],"finding_verdicts":[{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The flagged text is a Markdown Python code fence introducing an entity tracking example. It does not contain shell execution or user-controlled command construction.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The flagged backticks are the closing Markdown fence for the preceding Python example. There is no executable shell syntax or external command invocation.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:176:ruby-shell-backtick-execution","reason":"The flagged text is another Markdown Python code fence for a temporal query example. The example shows a database query pattern, not OS command execution.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:4:hardcoded-url","reason":"The URL appears only in frontmatter as source attribution for the skill. It is not used for runtime network access, data transfer, or remote loading.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:45:system-reconnaissance","reason":"The line explains that vector stores lose relationship information using a customer purchase example. It is conceptual architecture guidance, not system reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:52:system-reconnaissance","reason":"The line describes temporal validity fields for knowledge graphs. It does not request host, user, network, or environment discovery.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:100:system-reconnaissance","reason":"The address query is an example of temporal memory retrieval. It does not instruct the agent to inspect local system state or gather sensitive machine information.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:132:system-reconnaissance","reason":"The line discusses filtering memories by validity period. This is a normal retrieval concept and is unrelated to system reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:181:system-reconnaissance","reason":"The line is a parameterized Cypher WHERE clause inside a temporal graph example. It references an application user identifier, not local OS account discovery.","verdict":"false_positive","confidence":0.93}],"semantic_findings":[],"subject_marketplace_commit_sha":"816c62b2546ddb1c6a0453e7c781b5e095117819","subject_content_hash":"08acc6bd472ff178c40251591cb02155a3c6b50fbbeefe39b34f7eb99cf9c549","subject_tree_hash":"133891558dd36b26ec6856c555cb2efcee4ae20816e8133223de71bc1181da1c","subject_plugin_path":"skills/sickn33/memory-systems","audit_payload_hash":"28b32055ad5e7bc6b61f5da011206e37","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"816c62b2546ddb1c6a0453e7c781b5e095117819","contentHash":"08acc6bd472ff178c40251591cb02155a3c6b50fbbeefe39b34f7eb99cf9c549","treeHash":"133891558dd36b26ec6856c555cb2efcee4ae20816e8133223de71bc1181da1c","pluginPath":"skills/sickn33/memory-systems","auditPayloadHash":"28b32055ad5e7bc6b61f5da011206e37"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}