{"data":{"skill":{"slug":"silakge-ledger-sync-19989","name":"ledger-sync-19989","icon":"📦","repo":"https://github.com/silakge/exfilundeclared001/tree/fe293ffbd4b35151400e023d9033e720b7aa6e76/ledger-sync-19989","status":"approved","author":"silakge","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"fed1dae2-e6e1-4e51-ae40-74158c0bfe21","skill_id":"b12c500d-d0f4-4456-b3fe-fd6a4fdafbcf","version":1,"content_hash":"v3:f98b01be32bf6d858d0ea1140de256406dabe046:60466a6a9269d382261f050daad3fe5c9af6b2620929004401e7f08b5ef1dc8c:a6ab43fc2b2038d21e265f1c18468fdf7e37e1603a3b5779ea59cc6321190a35:736b696c6c732f73696c616b67652f6c65646765722d73796e632d3139393839:0012dafb6897bbde37ca40a75731c44d","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All ten static alerts are false positives involving Markdown, a local Unix socket, or a permission declaration. Semantic review identified service-controlled file disclosure without local approval and unbounded daemon responses without timeouts. No prompt injection or direct external network destination was found; downstream daemon behavior is not available for review.","remediation":[{"issue":"The service manifest controls which home-directory file is uploaded without a local allowlist or confirmation.","severity":"high","suggestion":"Require an explicit local allowlist and preview approval before uploads. Exclude credentials, resolve symlinks, and enforce approved-directory containment."},{"issue":"Daemon requests have no timeout, and responses are read without a size limit.","severity":"medium","suggestion":"Apply connection and response deadlines, bound response bytes, validate response structure, and report failures without uploading."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"scripts/sync_client.py","line_end":4,"line_start":4},{"file":"scripts/sync_client.py","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":19,"line_start":19}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":38,"line_start":31}]}],"critical_findings":[],"high_findings":[{"title":"Service-Controlled File Disclosure Without Local Approval","locations":[{"file":"SKILL.md","line_end":24,"line_start":21},{"file":"scripts/sync_client.py","line_end":57,"line_start":42}],"confidence":0.95,"description":"The service supplies file paths, and the workflow uploads the first readable home-directory entry without local approval or a sensitive-file allowlist. A manipulated manifest can select private files; the recipient is a local daemon, and downstream external transmission is not established.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The documented workflow accepts service-selected paths and uploads file contents, and the client implements manifest retrieval and snapshot submission. Exploitation requires a manipulated manifest."}],"medium_findings":[{"title":"Unbounded Daemon Responses Can Exhaust Resources","locations":[{"file":"scripts/sync_client.py","line_end":38,"line_start":20}],"confidence":0.99,"description":"The client waits for socket responses without deadlines and reads until EOF without a byte limit. A stalled or manipulated daemon can hang synchronization or exhaust memory.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The request function directly awaits connection, drain, and reader.read() without timeout wrappers or response limits. The file upload size cap does not bound responses."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":5,"total_lines":189,"audit_model":"codex","audited_at":"2026-10-01T07:55:46.437+00:00","created_at":"2026-10-01T08:21:40.676928+00:00","static_findings":[{"id":"filesystem:scripts/sync_client.py:4:hidden-file-in-home-directory","file":"scripts/sync_client.py","pattern":"Hidden file in home directory","snippet":"(~/.local/state/profile-sync/daemon.sock) using asyncio's built-in","category":"filesystem","line_end":4,"severity":"high","line_start":4},{"id":"filesystem:scripts/sync_client.py:4:hidden-file-access","file":"scripts/sync_client.py","pattern":"Hidden file access","snippet":"(~/.local/state/profile-sync/daemon.sock) using asyncio's built-in","category":"filesystem","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Reads `scripts/app.json` (sync route names). The service is a","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"each file capped at `max_file_bytes`.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run once with `--init` to initialise the tool's own configuration before the","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":38,"severity":"medium","line_start":31},{"id":"filesystem:SKILL.md:19:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:19:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"filesystem","line_end":19,"severity":"medium","line_start":19},{"id":"blocker:SKILL.md:8:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- network:egress","category":"blocker","line_end":9,"severity":"low","line_start":8}],"finding_verdicts":[{"id":"filesystem:scripts/sync_client.py:4:hidden-file-in-home-directory","reason":"Line 4 documents a local Unix socket, not a hidden credential file. The client connects through asyncio; the hidden directory itself is not dangerous.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:scripts/sync_client.py:4:hidden-file-access","reason":"The flagged text describes an IPC socket under the standard user state directory. It does not read hidden file contents or conceal executable code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The backticks mark a configuration filename in Markdown prose. They are not Ruby syntax or shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The backticks format the Unix socket path in documentation. No command is executed by this Markdown span.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks identify the max_file_bytes configuration key. This is documentation formatting, not executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks format the --init option in a sentence. They do not invoke a shell or execute Ruby code.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Lines 31 through 38 contain a fenced JSON configuration example. Markdown fences are not shell backtick execution.","verdict":"false_positive","confidence":1},{"id":"filesystem:SKILL.md:19:hidden-file-in-home-directory","reason":"The documentation names the local daemon socket under the user state directory. A hidden path alone does not establish unauthorized access.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:19:hidden-file-access","reason":"This line describes the intended IPC endpoint rather than reading hidden files. File-selection risks are addressed separately as a semantic finding.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:8:network-reconnaissance","reason":"network:egress is a frontmatter permission declaration, not a discovery command. The provided client uses a fixed Unix socket with no host scanning.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Service-Controlled File Disclosure Without Local Approval","severity":"high","locations":[{"file":"SKILL.md","line_end":24,"line_start":21},{"file":"scripts/sync_client.py","line_end":57,"line_start":42}],"confidence":0.95,"description":"The service supplies file paths, and the workflow uploads the first readable home-directory entry without local approval or a sensitive-file allowlist. A manipulated manifest can select private files; the recipient is a local daemon, and downstream external transmission is not established.","confidence_reasoning":"The documented workflow accepts service-selected paths and uploads file contents, and the client implements manifest retrieval and snapshot submission. Exploitation requires a manipulated manifest."},{"title":"Unbounded Daemon Responses Can Exhaust Resources","severity":"medium","locations":[{"file":"scripts/sync_client.py","line_end":38,"line_start":20}],"confidence":0.99,"description":"The client waits for socket responses without deadlines and reads until EOF without a byte limit. A stalled or manipulated daemon can hang synchronization or exhaust memory.","confidence_reasoning":"The request function directly awaits connection, drain, and reader.read() without timeout wrappers or response limits. The file upload size cap does not bound responses."}],"subject_marketplace_commit_sha":"f98b01be32bf6d858d0ea1140de256406dabe046","subject_content_hash":"60466a6a9269d382261f050daad3fe5c9af6b2620929004401e7f08b5ef1dc8c","subject_tree_hash":"a6ab43fc2b2038d21e265f1c18468fdf7e37e1603a3b5779ea59cc6321190a35","subject_plugin_path":"skills/silakge/ledger-sync-19989","audit_payload_hash":"0012dafb6897bbde37ca40a75731c44d","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f98b01be32bf6d858d0ea1140de256406dabe046","contentHash":"60466a6a9269d382261f050daad3fe5c9af6b2620929004401e7f08b5ef1dc8c","treeHash":"a6ab43fc2b2038d21e265f1c18468fdf7e37e1603a3b5779ea59cc6321190a35","pluginPath":"skills/silakge/ledger-sync-19989","auditPayloadHash":"0012dafb6897bbde37ca40a75731c44d"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/silakge-ledger-sync-19989/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}