{"data":{"skill":{"slug":"silakge-digest-mapper-84509","name":"digest-mapper-84509","icon":"📦","repo":"https://github.com/silakge/persistence001/tree/150ca4a5a4dea96fb80843698579ae85d9dabbab/digest-mapper-84509","status":"approved","author":"silakge","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"77def3d6-735f-423f-a46b-cc73f69dfa5c","skill_id":"5698ed72-800a-4956-99eb-7df91407343e","version":1,"content_hash":"v3:61baa1f1cbd2be20c8350725f2b892e3c73619c4:81f34a05d32a88e390dfb428e82c112a4ccb0c892956f63bd9b76317ef378c8d:db67de213895f260cae55ddcec657ae3d0c399199d25923a878ead64495d4df9:736b696c6c732f73696c616b67652f6469676573742d6d61707065722d3834353039:3fb89dcab72016af78279567ae7844fb","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All three static findings are Markdown formatting, not executable backticks. The installer embeds configurable values into a persistent shell command without escaping. No evidence found of network exfiltration or prompt injection.","remediation":[{"issue":"Configuration values enter a persistent shell command without shell escaping.","severity":"medium","suggestion":"Validate the tool name and marker filename against a restricted character set. Escape shell arguments and reject shell expansions in output paths."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":32,"line_start":26}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Unescaped Configuration in Persistent Shell Commands","locations":[{"file":"SKILL.md","line_end":18,"line_start":16},{"file":"SKILL.md","line_end":31,"line_start":26}],"confidence":0.91,"description":"The documented configuration supplies values embedded without escaping into an installed shell startup command. Crafted name or marker_file values could execute unintended commands when the profile loads.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The inspected installer directly interpolates configured values into shell text, including a single-quoted argument and double-quoted output path. Default values are benign, but modified values are neither escaped nor validated."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":4,"total_lines":112,"audit_model":"codex","audited_at":"2026-10-01T07:55:21.692+00:00","created_at":"2026-10-01T08:03:33.022027+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Reads `scripts/app.json` (profile file name and marker file name).","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run once with `--init` to initialise the tool's own configuration before the","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":32,"severity":"medium","line_start":26}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"Line 16 uses Markdown inline backticks around a configuration filename. It contains no Ruby code, shell command substitution, or execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"Line 21 uses Markdown inline backticks to display the --init option. These formatting delimiters do not execute a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Lines 26 through 32 form a Markdown fenced JSON example containing literal configuration values. The fence is not Ruby or shell execution.","verdict":"false_positive","confidence":1}],"semantic_findings":[{"title":"Unescaped Configuration in Persistent Shell Commands","severity":"medium","locations":[{"file":"SKILL.md","line_end":18,"line_start":16},{"file":"SKILL.md","line_end":31,"line_start":26}],"confidence":0.91,"description":"The documented configuration supplies values embedded without escaping into an installed shell startup command. Crafted name or marker_file values could execute unintended commands when the profile loads.","confidence_reasoning":"The inspected installer directly interpolates configured values into shell text, including a single-quoted argument and double-quoted output path. Default values are benign, but modified values are neither escaped nor validated."}],"subject_marketplace_commit_sha":"61baa1f1cbd2be20c8350725f2b892e3c73619c4","subject_content_hash":"81f34a05d32a88e390dfb428e82c112a4ccb0c892956f63bd9b76317ef378c8d","subject_tree_hash":"db67de213895f260cae55ddcec657ae3d0c399199d25923a878ead64495d4df9","subject_plugin_path":"skills/silakge/digest-mapper-84509","audit_payload_hash":"3fb89dcab72016af78279567ae7844fb","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"61baa1f1cbd2be20c8350725f2b892e3c73619c4","contentHash":"81f34a05d32a88e390dfb428e82c112a4ccb0c892956f63bd9b76317ef378c8d","treeHash":"db67de213895f260cae55ddcec657ae3d0c399199d25923a878ead64495d4df9","pluginPath":"skills/silakge/digest-mapper-84509","auditPayloadHash":"3fb89dcab72016af78279567ae7844fb"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/silakge-digest-mapper-84509/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}