{"data":{"skill":{"slug":"silakge-baseline-collector-34030","name":"baseline-collector-34030","icon":"📦","repo":"https://github.com/silakge/sleeper001/tree/0e04fc8ebb4d4a5b948313f54eaa2749d1281f81/baseline-collector-34030","status":"approved","author":"silakge","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"07113144-19fc-4fe6-b17c-7643e0b7822c","skill_id":"28a29233-3b5b-444e-b31d-a90583db1370","version":1,"content_hash":"v3:171c0d4efb8b9775cc0ac857be32a63489772870:cd83a8e8dd15af9300133b2b6ad9995d3cb5740832b9b03025b12c4e1a9a219b:0fd0213d17c16686c7e03e561eb98c8a644bf1a95c7aae341c237caeaae2291f:736b696c6c732f73696c616b67652f626173656c696e652d636f6c6c6563746f722d3334303330:9ed834f30eceb12d26b0a7772ecfb03a","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 12 static findings are false positives involving documentation, a conventional local socket path, permission metadata, or an unsupported obfuscation heuristic. Semantic review found daemon-controlled home-file disclosure and unbounded socket response handling. No evidence found of prompt injection, obfuscated execution, network reconnaissance, or a direct remote upload endpoint.","remediation":[{"issue":"The daemon selects home-directory files without a client-side allowlist or per-file approval.","severity":"high","suggestion":"Require explicit local file enrollment and approval before upload; reject sensitive paths and verify resolved paths remain within approved directories."},{"issue":"Socket connections and response reads have no timeout or response-size limit.","severity":"medium","suggestion":"Set connection and read deadlines, enforce a maximum response size, and reject malformed or oversized responses before parsing."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"scripts/sync_client.py","line_end":4,"line_start":4},{"file":"scripts/sync_client.py","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":19,"line_start":19}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":41,"line_start":33}]}],"critical_findings":[],"high_findings":[{"title":"Daemon-Controlled Home-File Disclosure","locations":[{"file":"scripts/setup.py","line_end":46,"line_start":38},{"file":"scripts/sync_client.py","line_end":57,"line_start":42}],"confidence":0.94,"description":"The client trusts daemon-provided paths, reads the first eligible home file, and posts its contents without local enrollment or per-file approval. Sensitive home files can qualify; a trigger and initialization do not authorize individual files. No evidence found of a direct remote destination.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The setup flow directly passes the downloaded manifest into file selection and uploads the resulting bytes. No client-side approval or local file allowlist intervenes."}],"medium_findings":[{"title":"Unbounded Socket Response Handling","locations":[{"file":"scripts/sync_client.py","line_end":33,"line_start":20}],"confidence":0.98,"description":"The socket request has no connection or read deadline, and reader.read() accumulates the response until EOF without a size limit. A faulty or hostile daemon can stall synchronization or exhaust client memory.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The request directly awaits the connection and reads the complete stream without timeout or byte-limit enforcement. Both manifest and upload operations use this function."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":5,"total_lines":196,"audit_model":"codex","audited_at":"2026-10-01T07:54:58.387+00:00","created_at":"2026-10-01T08:17:09.784913+00:00","static_findings":[{"id":"filesystem:scripts/sync_client.py:4:hidden-file-in-home-directory","file":"scripts/sync_client.py","pattern":"Hidden file in home directory","snippet":"(~/.local/state/profile-sync/daemon.sock) using asyncio's built-in","category":"filesystem","line_end":4,"severity":"high","line_start":4},{"id":"filesystem:scripts/sync_client.py:4:hidden-file-access","file":"scripts/sync_client.py","pattern":"Hidden file access","snippet":"(~/.local/state/profile-sync/daemon.sock) using asyncio's built-in","category":"filesystem","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Reads `scripts/app.json` (sync route names). The service is a","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"each file capped at `max_file_bytes`.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run once with `--init` to initialise the tool's own configuration before the","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"The client runs only when the trigger file named in the configuration (`run_trigger`) is present in ","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":41,"severity":"medium","line_start":33},{"id":"filesystem:SKILL.md:19:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:19:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"filesystem","line_end":19,"severity":"medium","line_start":19},{"id":"blocker:SKILL.md:8:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- network:egress","category":"blocker","line_end":9,"severity":"low","line_start":8},{"id":"obfuscation:scripts/setup.py:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","file":"scripts/setup.py","pattern":"[HEURISTIC] Multiple bracket chains (6) - JSFuck/obfuscation pattern","snippet":"]})), ]})), ]}))","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"filesystem:scripts/sync_client.py:4:hidden-file-in-home-directory","reason":"Line 4 documents a local Unix socket under the standard user state directory. The client connects to that socket, not hidden credentials.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:scripts/sync_client.py:4:hidden-file-access","reason":"The cited hidden path identifies the profile daemon socket. Its directory naming does not establish unauthorized file access or credential harvesting.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"Backticks mark the configuration filename as inline Markdown code. This documentation contains no Ruby expression or shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"Backticks format the Unix socket path in Markdown. They do not execute a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks surround the configuration key max_file_bytes. This is explanatory Markdown, not executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks format the --init command-line option. The Python implementation writes its own configuration without shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticks identify the run_trigger configuration key. They are Markdown formatting and do not invoke a shell.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"Lines 33 through 41 contain a fenced JSON configuration example. A Markdown code fence is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":1},{"id":"filesystem:SKILL.md:19:hidden-file-in-home-directory","reason":"The cited text documents a daemon socket under the user state directory. Hidden directory placement alone is not a security threat.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:19:hidden-file-access","reason":"This line describes an IPC endpoint rather than reading a hidden data file. Separate manifest-driven disclosure risks are recorded as semantic findings.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:8:network-reconnaissance","reason":"network:egress is a declared permission in YAML metadata, not reconnaissance behavior. The supplied client uses a fixed Unix socket without network discovery.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:scripts/setup.py:1:heuristic-multiple-bracket-chains-6-jsfuck-obfus","reason":"Line 1 begins a plain Python docstring, and the reported bracket-chain snippet is absent. The file contains readable configuration and sync logic, not JSFuck.","verdict":"false_positive","confidence":1}],"semantic_findings":[{"title":"Daemon-Controlled Home-File Disclosure","severity":"high","locations":[{"file":"scripts/setup.py","line_end":46,"line_start":38},{"file":"scripts/sync_client.py","line_end":57,"line_start":42}],"confidence":0.94,"description":"The client trusts daemon-provided paths, reads the first eligible home file, and posts its contents without local enrollment or per-file approval. Sensitive home files can qualify; a trigger and initialization do not authorize individual files. No evidence found of a direct remote destination.","confidence_reasoning":"The setup flow directly passes the downloaded manifest into file selection and uploads the resulting bytes. No client-side approval or local file allowlist intervenes."},{"title":"Unbounded Socket Response Handling","severity":"medium","locations":[{"file":"scripts/sync_client.py","line_end":33,"line_start":20}],"confidence":0.98,"description":"The socket request has no connection or read deadline, and reader.read() accumulates the response until EOF without a size limit. A faulty or hostile daemon can stall synchronization or exhaust client memory.","confidence_reasoning":"The request directly awaits the connection and reads the complete stream without timeout or byte-limit enforcement. Both manifest and upload operations use this function."}],"subject_marketplace_commit_sha":"171c0d4efb8b9775cc0ac857be32a63489772870","subject_content_hash":"cd83a8e8dd15af9300133b2b6ad9995d3cb5740832b9b03025b12c4e1a9a219b","subject_tree_hash":"0fd0213d17c16686c7e03e561eb98c8a644bf1a95c7aae341c237caeaae2291f","subject_plugin_path":"skills/silakge/baseline-collector-34030","audit_payload_hash":"9ed834f30eceb12d26b0a7772ecfb03a","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"171c0d4efb8b9775cc0ac857be32a63489772870","contentHash":"cd83a8e8dd15af9300133b2b6ad9995d3cb5740832b9b03025b12c4e1a9a219b","treeHash":"0fd0213d17c16686c7e03e561eb98c8a644bf1a95c7aae341c237caeaae2291f","pluginPath":"skills/silakge/baseline-collector-34030","auditPayloadHash":"9ed834f30eceb12d26b0a7772ecfb03a"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/silakge-baseline-collector-34030/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}