{"data":{"skill":{"slug":"sickn33-miro-automation","name":"miro-automation","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/miro-automation","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"1808de80-f8ec-4535-8565-fa569b147900","skill_id":"f6a45480-7e75-4c6b-9b1c-098a2331a6dc","version":6,"content_hash":"v3:81e05e636292629114b76cbb3922fbe57672fc02:a741d82f74665aa942e529190152271f5f01b850db0a75425e12ec96e2c90752:2e49c0b52b94c36d11ed069ecc6596a472a4c4f23829aa959168f4e4728d59e9:736b696c6c732f7369636b6e33332f6d69726f2d6175746f6d6174696f6e:b6ffc9ad56a25d885177545d8cf87773","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 54 shell-execution alerts and seven reconnaissance alerts are false positives caused by Markdown and Miro terminology. The external Rube endpoint is a real trust boundary. State-changing and sharing actions also need explicit confirmation.","remediation":[{"issue":"Rube MCP and Composio receive delegated Miro access and board data.","severity":"medium","suggestion":"Disclose third-party data handling, recommend least-privilege Miro authorization, and tell users how to review or revoke the connection."},{"issue":"Create, bulk-update, and share workflows lack an immediate confirmation step.","severity":"medium","suggestion":"Show the target board, proposed changes, recipients, and roles before calling any state-changing tool, then require explicit user approval."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":91,"line_start":91},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":122,"line_start":122},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":126,"line_start":126},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":128,"line_start":128},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":146,"line_start":142},{"file":"SKILL.md","line_end":149,"line_start":146},{"file":"SKILL.md","line_end":153,"line_start":149},{"file":"SKILL.md","line_end":157,"line_start":153},{"file":"SKILL.md","line_end":157,"line_start":157}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":21,"line_start":21}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Third-Party MCP Handles Delegated Miro Access","locations":[{"file":"SKILL.md","line_end":11,"line_start":11},{"file":"SKILL.md","line_end":26,"line_start":21}],"confidence":0.97,"description":"Miro authentication and operations pass through Rube MCP and Composio, exposing delegated account access and board data to an additional service provider.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The skill explicitly names Composio, directs installation of the Rube MCP endpoint, and requires Miro OAuth through the returned authentication link."},{"title":"No Explicit Confirmation for External Side Effects","locations":[{"file":"SKILL.md","line_end":59,"line_start":51},{"file":"SKILL.md","line_end":109,"line_start":96}],"confidence":0.95,"description":"Board creation, bulk content changes, and access grants can alter a workspace, but the workflows do not require confirmation immediately before execution.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The documented workflows invoke create and share tools with user-selected targets, yet neither section includes a preview or final approval requirement."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":21,"line_start":21}],"confidence":0.96,"description":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill explicitly instructs users to add the external https://rube.app/mcp endpoint. This expected integration creates a real third-party network and authentication trust boundary."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":215,"audit_model":"codex","audited_at":"2026-08-04T14:20:34.34+00:00","created_at":"2026-08-05T01:15:02.557671+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Active Miro connection via `RUBE_MANAGE_CONNECTIONS` with toolkit `miro`","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Always call `RUBE_SEARCH_TOOLS` first to get current tool schemas","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `miro`","category":"external_commands","line_end":25,"severity":"medium","line_start":25},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIRO_GET_BOARDS2` - List all accessible boards [Required]","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIRO_GET_BOARD` - Get detailed info for a specific board [Optional]","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `query`: Search term to filter boards by name","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `sort`: Sort by 'default', 'last_modified', 'last_opened', 'last_created', 'alphabetically'","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `limit`: Number of results per page (max 50)","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `offset`: Pagination offset","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `board_id`: Specific board ID for detailed retrieval","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIRO_CREATE_BOARD` - Create a new empty board [Optional]","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIRO_CREATE_STICKY_NOTE_ITEM` - Add sticky notes to a board [Optional]","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `MIRO_CREATE_FRAME_ITEM2` - Add frames to organize content [Optional]","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `MIRO_CREATE_ITEMS_IN_BULK` - Add multiple items at once [Optional]","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `name` / `description`: Board name and description (for CREATE_BOARD)","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `board_id`: Target board ID (required for all item creation)","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `data`: Content object with `content` field for sticky note text","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `style`: Styling object with `fillColor` for sticky note color","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `position`: Object with `x` and `y` coordinates","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `geometry`: Object with `width` and `height`","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `board_id` is required for ALL item operations; resolve via GET_BOARDS2 first","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Sticky note colors use hex codes (e.g., '#FF0000') in the `fillColor` field","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Frame items require `geometry` with both width and height","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIRO_GET_BOARD_ITEMS` - List all items on a board [Required]","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIRO_GET_CONNECTORS2` - List connections between items [Optional]","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `board_id`: Target board ID (required)","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `type`: Filter by item type ('sticky_note', 'shape', 'text', 'frame', 'image', 'card')","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `limit`: Number of items per page","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `cursor`: Pagination cursor from previous response","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Results are paginated; follow `cursor` until absent for complete item list","category":"external_commands","line_end":91,"severity":"medium","line_start":91},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIRO_GET_BOARDS2` - Find the board to share [Prerequisite]","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIRO_SHARE_BOARD` - Share the board with users [Required]","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `MIRO_GET_BOARD_MEMBERS` - Verify current board members [Optional]","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `board_id`: Board to share (required)","category":"external_commands","line_end":106,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `emails`: Array of email addresses to invite","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `role`: Access level ('viewer', 'commenter', 'editor')","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `message`: Optional invitation message","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `MIRO_GET_BOARD_ITEMS` - Find items to connect [Prerequisite]","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `MIRO_GET_CONNECTORS2` - View existing connections [Optional]","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `board_id`: Target board ID","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `startItem`: Object with `id` of the source item","category":"external_commands","line_end":127,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `endItem`: Object with `id` of the target item","category":"external_commands","line_end":128,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `style`: Connector style (line type, color, arrows)","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":146,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":149,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":153,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":157,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Boards: Use `offset` and `limit` (offset-based)","category":"external_commands","line_end":157,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Board items: Use `cursor` and `limit` (cursor-based)","category":"external_commands","line_end":158,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `position: {x: 0, y: 0}` for center of board","category":"external_commands","line_end":179,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Sticky notes need `data.content` for text","category":"external_commands","line_end":180,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Frames need `geometry.width` and `geometry.height`","category":"external_commands","line_end":180,"severity":"medium","line_start":180},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"blocker:SKILL.md:112:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Email addresses must be valid; invalid emails cause the entire request to fail","category":"blocker","line_end":112,"severity":"low","line_start":112},{"id":"blocker:SKILL.md:145:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"3. Extract id field","category":"blocker","line_end":145,"severity":"low","line_start":145},{"id":"blocker:SKILL.md:150:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"1. Call MIRO_GET_BOARD_ITEMS with board_id and optional type filter","category":"blocker","line_end":150,"severity":"low","line_start":150},{"id":"blocker:SKILL.md:152:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"3. Extract item id for further operations","category":"blocker","line_end":152,"severity":"low","line_start":152},{"id":"blocker:SKILL.md:198:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Get board details | MIRO_GET_BOARD | board_id |","category":"blocker","line_end":198,"severity":"low","line_start":198},{"id":"blocker:SKILL.md:205:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Get members | MIRO_GET_BOARD_MEMBERS | board_id |","category":"blocker","line_end":205,"severity":"low","line_start":205},{"id":"blocker:SKILL.md:206:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Get connectors | MIRO_GET_CONNECTORS2 | board_id |","category":"blocker","line_end":206,"severity":"low","line_start":206}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:25:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:91:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code-fence delimiters around numbered workflow prose. They do not execute Ruby, shell commands, or any other code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code-fence delimiters around numbered workflow prose. They do not execute Ruby, shell commands, or any other code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code-fence delimiters around numbered workflow prose. They do not execute Ruby, shell commands, or any other code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code-fence delimiters around numbered workflow prose. They do not execute Ruby, shell commands, or any other code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The backticks format an MCP tool name, parameter, value, or data example as inline Markdown. No Ruby or shell execution syntax is present.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The skill explicitly instructs users to add the external https://rube.app/mcp endpoint. This expected integration creates a real third-party network and authentication trust boundary.","verdict":"confirmed","severity":"low","confidence":0.96},{"id":"blocker:SKILL.md:112:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:145:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:150:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:152:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:198:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:205:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:206:system-reconnaissance","reason":"The matched text describes Miro input validation, API result lookup, or a Miro tool reference. It does not inspect the host, network, environment, or installed software.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Third-Party MCP Handles Delegated Miro Access","severity":"medium","locations":[{"file":"SKILL.md","line_end":11,"line_start":11},{"file":"SKILL.md","line_end":26,"line_start":21}],"confidence":0.97,"description":"Miro authentication and operations pass through Rube MCP and Composio, exposing delegated account access and board data to an additional service provider.","confidence_reasoning":"The skill explicitly names Composio, directs installation of the Rube MCP endpoint, and requires Miro OAuth through the returned authentication link."},{"title":"No Explicit Confirmation for External Side Effects","severity":"medium","locations":[{"file":"SKILL.md","line_end":59,"line_start":51},{"file":"SKILL.md","line_end":109,"line_start":96}],"confidence":0.95,"description":"Board creation, bulk content changes, and access grants can alter a workspace, but the workflows do not require confirmation immediately before execution.","confidence_reasoning":"The documented workflows invoke create and share tools with user-selected targets, yet neither section includes a preview or final approval requirement."}],"subject_marketplace_commit_sha":"81e05e636292629114b76cbb3922fbe57672fc02","subject_content_hash":"a741d82f74665aa942e529190152271f5f01b850db0a75425e12ec96e2c90752","subject_tree_hash":"2e49c0b52b94c36d11ed069ecc6596a472a4c4f23829aa959168f4e4728d59e9","subject_plugin_path":"skills/sickn33/miro-automation","audit_payload_hash":"b6ffc9ad56a25d885177545d8cf87773","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"81e05e636292629114b76cbb3922fbe57672fc02","contentHash":"a741d82f74665aa942e529190152271f5f01b850db0a75425e12ec96e2c90752","treeHash":"2e49c0b52b94c36d11ed069ecc6596a472a4c4f23829aa959168f4e4728d59e9","pluginPath":"skills/sickn33/miro-automation","auditPayloadHash":"b6ffc9ad56a25d885177545d8cf87773"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-miro-automation/audits/6/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}