{"data":{"skill":{"slug":"sickn33-mermaid-expert","name":"mermaid-expert","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/mermaid-expert","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"ea98a60a-959d-493e-b9e3-691574e225c6","skill_id":"2eb1dcea-e46b-439a-95a0-d104f4648d96","version":4,"content_hash":"v3:816c62b2546ddb1c6a0453e7c781b5e095117819:bfdf098f4a0fc8acadf3535e8020996232a6e2b074a44c016b8656ea4a018153:8d700bf74b4921c02296e0a67622118190e0983cfc629c7ae84ac3f176460c03:736b696c6c732f7369636b6e33332f6d65726d6169642d657870657274:4c8639521296cb82c59bd8e82f90db6c","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All static findings appear to be false positives. The backtick alerts are Markdown inline code and a fenced list of Mermaid diagram types, not shell execution. No prompt injection or malicious intent evidence was found in SKILL.md.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":42,"line_start":38}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":60,"audit_model":"codex","audited_at":"2026-07-07T00:25:25.122+00:00","created_at":"2026-07-17T20:10:11.66113+00:00","static_findings":[{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- If detailed examples are required, open `resources/implementation-playbook.md`.","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":42,"severity":"medium","line_start":38},{"id":"blocker:SKILL.md:3:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"description: Create Mermaid diagrams for flowcharts, sequences, ERDs, and","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"blocker:SKILL.md:12:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Working on mermaid expert tasks or workflows","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"blocker:SKILL.md:13:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Needing guidance, best practices, or checklists for mermaid expert","category":"blocker","line_end":13,"severity":"low","line_start":13},{"id":"blocker:SKILL.md:17:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- The task is unrelated to mermaid expert","category":"blocker","line_end":17,"severity":"low","line_start":17},{"id":"blocker:SKILL.md:27:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"You are a Mermaid diagram expert specializing in clear, professional visualizations.","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:SKILL.md:46:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. Keep diagrams readable - avoid overcrowding","category":"blocker","line_end":46,"severity":"low","line_start":46},{"id":"blocker:SKILL.md:52:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Complete Mermaid diagram code","category":"blocker","line_end":52,"severity":"low","line_start":52}],"finding_verdicts":[{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The backticks only format a relative Markdown path in prose. There is no Ruby code, shell command, or instruction to execute the path.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The flagged backticks are a Markdown code fence around static Mermaid diagram type names. The block contains no executable shell syntax.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:3:system-reconnaissance","reason":"This is frontmatter description for Mermaid diagram creation. The phrase describes system diagrams as documentation content, not host reconnaissance.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:12:system-reconnaissance","reason":"This line is generic activation guidance for Mermaid workflows. It does not ask the assistant to inspect the host system or collect environment details.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:13:system-reconnaissance","reason":"This line describes when a user may need Mermaid guidance. It contains no reconnaissance request, sensitive data request, or system probing instruction.","verdict":"false_positive","confidence":0.94},{"id":"blocker:SKILL.md:17:system-reconnaissance","reason":"This is a boundary statement for unrelated tasks. It does not direct the assistant to inspect files, processes, networks, or system configuration.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:27:system-reconnaissance","reason":"This is a normal role description for the Mermaid diagram domain. It does not request privilege escalation, context override, or security analysis bypass.","verdict":"false_positive","confidence":0.9},{"id":"blocker:SKILL.md:46:system-reconnaissance","reason":"This line is a readability recommendation for diagrams. It has no relationship to host reconnaissance or malicious discovery behavior.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:52:system-reconnaissance","reason":"This output requirement asks for Mermaid diagram code as user-facing documentation. It does not request execution, system inspection, or data collection.","verdict":"false_positive","confidence":0.96}],"semantic_findings":[],"subject_marketplace_commit_sha":"816c62b2546ddb1c6a0453e7c781b5e095117819","subject_content_hash":"bfdf098f4a0fc8acadf3535e8020996232a6e2b074a44c016b8656ea4a018153","subject_tree_hash":"8d700bf74b4921c02296e0a67622118190e0983cfc629c7ae84ac3f176460c03","subject_plugin_path":"skills/sickn33/mermaid-expert","audit_payload_hash":"4c8639521296cb82c59bd8e82f90db6c","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"816c62b2546ddb1c6a0453e7c781b5e095117819","contentHash":"bfdf098f4a0fc8acadf3535e8020996232a6e2b074a44c016b8656ea4a018153","treeHash":"8d700bf74b4921c02296e0a67622118190e0983cfc629c7ae84ac3f176460c03","pluginPath":"skills/sickn33/mermaid-expert","auditPayloadHash":"4c8639521296cb82c59bd8e82f90db6c"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}