{"data":{"skill":{"slug":"silakge-manifest-helper-35157","name":"manifest-helper-35157","icon":"📦","repo":"https://github.com/silakge/exfildeclared001/tree/645784ad22c0dcdd8282fa3f4187f6e158780810/manifest-helper-35157","status":"approved","author":"silakge","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"2cda2c33-b20d-4d66-866a-ed686f6a6f4b","skill_id":"cfccb961-33a6-4985-9ecc-18f1f7e3dcc2","version":1,"content_hash":"v3:e9e41eda70f8ac8cb3173ba9ac8d456122374a8b:8c3f50e976d19bc900a667a81f3fb422e0240eb76e9a6645ae66f2b0ddac07e1:85ea2187032a395cc231a6c93826dde89dd2ca6ca47210add9e1e7948ae3b07c:736b696c6c732f73696c616b67652f6d616e69666573742d68656c7065722d3335313537:ea7771f56190cc05d034b077b033a5af","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All ten static findings are false positives involving Markdown formatting, a local socket path, or a declared egress permission. Semantic review found service-directed file disclosure, unverified daemon security assumptions, and unbounded response handling. No evidence found of prompt injection or direct external network transmission by this client.","remediation":[{"issue":"The service controls which home-relative file becomes an uploaded snapshot without a local approval boundary.","severity":"high","suggestion":"Require a user-approved local file allowlist and upload preview; exclude credentials and resolve symbolic links before enforcing approved directory boundaries."},{"issue":"The client assumes owner-only socket access without verifying the socket or connected daemon.","severity":"medium","suggestion":"Verify socket type, ownership, restrictive permissions, and parent directory security; validate peer credentials where supported before exchanging manifests or file contents."},{"issue":"Daemon responses have no read deadline or size limit.","severity":"medium","suggestion":"Apply connection and read timeouts, cap response bytes, and validate manifest structure and path counts before processing."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"scripts/sync_client.py","line_end":4,"line_start":4},{"file":"scripts/sync_client.py","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":19,"line_start":19}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":38,"line_start":31}]}],"critical_findings":[],"high_findings":[{"title":"Service-Controlled File Selection Without Local Approval","locations":[{"file":"SKILL.md","line_end":24,"line_start":21},{"file":"scripts/sync_client.py","line_end":48,"line_start":42},{"file":"scripts/sync_client.py","line_end":57,"line_start":53}],"confidence":0.96,"description":"The service supplies home-relative file paths, and the first eligible file becomes an uploaded snapshot. No local allowlist or upload confirmation constrains selection, so a compromised daemon can request sensitive home files.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"Documentation and implementation establish the manifest-to-file-to-upload workflow without a client-side approval boundary. External forwarding and deliberate malicious intent are not established."}],"medium_findings":[{"title":"Unverified Daemon Identity and Socket Permissions","locations":[{"file":"scripts/sync_client.py","line_end":11,"line_start":8},{"file":"scripts/sync_client.py","line_end":21,"line_start":17}],"confidence":0.9,"description":"The client claims owner-only socket protection but connects to a fixed pathname without checking ownership, mode, or peer credentials. A substituted or misconfigured endpoint can supply manifests and receive snapshots.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The client contains a security assumption but no corresponding endpoint checks. Exploitability depends on daemon provisioning and filesystem permissions absent from this package."},{"title":"Unbounded Daemon Response Handling","locations":[{"file":"scripts/sync_client.py","line_end":39,"line_start":20}],"confidence":0.97,"description":"The client reads until EOF without a timeout or response-size limit. A faulty or hostile daemon can stall synchronization or exhaust memory.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"reader.read() requests the complete response, and the request routine applies no deadline or cumulative byte cap. The daemon controls response length and closure."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":5,"total_lines":189,"audit_model":"codex","audited_at":"2026-10-01T07:55:54.003+00:00","created_at":"2026-10-01T08:13:06.178235+00:00","static_findings":[{"id":"filesystem:scripts/sync_client.py:4:hidden-file-in-home-directory","file":"scripts/sync_client.py","pattern":"Hidden file in home directory","snippet":"(~/.local/state/profile-sync/daemon.sock) using asyncio's built-in","category":"filesystem","line_end":4,"severity":"high","line_start":4},{"id":"filesystem:scripts/sync_client.py:4:hidden-file-access","file":"scripts/sync_client.py","pattern":"Hidden file access","snippet":"(~/.local/state/profile-sync/daemon.sock) using asyncio's built-in","category":"filesystem","line_end":4,"severity":"medium","line_start":4},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Reads `scripts/app.json` (sync route names). The service is a","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"each file capped at `max_file_bytes`.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run once with `--init` to initialise the tool's own configuration before the","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":38,"severity":"medium","line_start":31},{"id":"filesystem:SKILL.md:19:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:19:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"(`~/.local/state/profile-sync/daemon.sock`, owner-only permissions --","category":"filesystem","line_end":19,"severity":"medium","line_start":19},{"id":"blocker:SKILL.md:8:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- network:egress","category":"blocker","line_end":9,"severity":"low","line_start":8}],"finding_verdicts":[{"id":"filesystem:scripts/sync_client.py:4:hidden-file-in-home-directory","reason":"Line 4 documents a local daemon socket, and lines 17-21 connect to that socket rather than reading hidden personal files. This path alone is not evidence of credential access or concealment.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:scripts/sync_client.py:4:hidden-file-access","reason":"The hidden directory holds the documented IPC socket, not a secret file targeted for extraction. Broader manifest and daemon trust risks are recorded separately.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"Backticks mark an inline configuration filename in Markdown. The line contains no Ruby expression, shell substitution, or execution instruction.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"Backticks format the Unix socket pathname in documentation. They do not execute a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The backticks format the max_file_bytes configuration key. No executable shell or Ruby syntax appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks format the documented --init option. This is Markdown prose, not shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"Lines 31-38 contain a fenced JSON configuration example. The fence is Markdown syntax and does not execute its contents.","verdict":"false_positive","confidence":1},{"id":"filesystem:SKILL.md:19:hidden-file-in-home-directory","reason":"The line documents an IPC endpoint under the user state directory, not access to hidden credentials. Unverified permission claims are assessed separately.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:19:hidden-file-access","reason":"This is documentation of a local Unix socket location. A hidden state directory is not itself a dangerous file-access operation.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:8:network-reconnaissance","reason":"The line declares network:egress permission in frontmatter. No reconnaissance, scanning, or host discovery is present.","verdict":"false_positive","confidence":1}],"semantic_findings":[{"title":"Service-Controlled File Selection Without Local Approval","severity":"high","locations":[{"file":"SKILL.md","line_end":24,"line_start":21},{"file":"scripts/sync_client.py","line_end":48,"line_start":42},{"file":"scripts/sync_client.py","line_end":57,"line_start":53}],"confidence":0.96,"description":"The service supplies home-relative file paths, and the first eligible file becomes an uploaded snapshot. No local allowlist or upload confirmation constrains selection, so a compromised daemon can request sensitive home files.","confidence_reasoning":"Documentation and implementation establish the manifest-to-file-to-upload workflow without a client-side approval boundary. External forwarding and deliberate malicious intent are not established."},{"title":"Unverified Daemon Identity and Socket Permissions","severity":"medium","locations":[{"file":"scripts/sync_client.py","line_end":11,"line_start":8},{"file":"scripts/sync_client.py","line_end":21,"line_start":17}],"confidence":0.9,"description":"The client claims owner-only socket protection but connects to a fixed pathname without checking ownership, mode, or peer credentials. A substituted or misconfigured endpoint can supply manifests and receive snapshots.","confidence_reasoning":"The client contains a security assumption but no corresponding endpoint checks. Exploitability depends on daemon provisioning and filesystem permissions absent from this package."},{"title":"Unbounded Daemon Response Handling","severity":"medium","locations":[{"file":"scripts/sync_client.py","line_end":39,"line_start":20}],"confidence":0.97,"description":"The client reads until EOF without a timeout or response-size limit. A faulty or hostile daemon can stall synchronization or exhaust memory.","confidence_reasoning":"reader.read() requests the complete response, and the request routine applies no deadline or cumulative byte cap. The daemon controls response length and closure."}],"subject_marketplace_commit_sha":"e9e41eda70f8ac8cb3173ba9ac8d456122374a8b","subject_content_hash":"8c3f50e976d19bc900a667a81f3fb422e0240eb76e9a6645ae66f2b0ddac07e1","subject_tree_hash":"85ea2187032a395cc231a6c93826dde89dd2ca6ca47210add9e1e7948ae3b07c","subject_plugin_path":"skills/silakge/manifest-helper-35157","audit_payload_hash":"ea7771f56190cc05d034b077b033a5af","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"e9e41eda70f8ac8cb3173ba9ac8d456122374a8b","contentHash":"8c3f50e976d19bc900a667a81f3fb422e0240eb76e9a6645ae66f2b0ddac07e1","treeHash":"85ea2187032a395cc231a6c93826dde89dd2ca6ca47210add9e1e7948ae3b07c","pluginPath":"skills/silakge/manifest-helper-35157","auditPayloadHash":"ea7771f56190cc05d034b077b033a5af"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/silakge-manifest-helper-35157/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":3,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}