{"data":{"skill":{"slug":"tencentcloudbase-relational-database-web-cloudbase","name":"relational-database-web-cloudbase","icon":"📦","repo":"https://github.com/tencentcloudbase/skills/tree/main/skills/relational-database-web","status":"approved","author":"tencentcloudbase","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"2274b2c4-667d-4bf8-9b3a-0ba537219f83","skill_id":"023cfba2-3a8d-42ea-b4eb-9b9e1fd0fd2f","version":1,"content_hash":"v2:24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec:3ff148a16c27c85bb668c6716d33f1f5a47652556b2a5d38413ae91dd182567a:858d1a9d8143d0a6cad0244e012e98be06292a468917e4c9749ca07d0a2a7dbb:689a5f90759afad9d2f0e8e17c85446c","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings are Markdown false positives from inline code, code fences, and fixed sibling references. The raw fallback URLs are a real concern because they can direct agents to mutable external instructions outside the reviewed package. No evidence of prompt injection, credential exfiltration, or automatic command execution was found.","remediation":[{"issue":"Mutable remote instruction fallbacks","severity":"medium","suggestion":"Pin fallback URLs to immutable commit hashes or package the referenced sibling skills with this skill."},{"issue":"Out-of-package sibling references","severity":"low","suggestion":"Declare sibling skill dependencies explicitly or replace parent-directory references with packaged local references."}],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"SKILL.md","line_end":87,"line_start":87}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":67,"line_start":65},{"file":"SKILL.md","line_end":71,"line_start":67},{"file":"SKILL.md","line_end":82,"line_start":71},{"file":"SKILL.md","line_end":87,"line_start":82},{"file":"SKILL.md","line_end":88,"line_start":87},{"file":"SKILL.md","line_end":89,"line_start":88},{"file":"SKILL.md","line_end":97,"line_start":89},{"file":"SKILL.md","line_end":99,"line_start":97},{"file":"SKILL.md","line_end":105,"line_start":99},{"file":"SKILL.md","line_end":107,"line_start":105},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":120,"line_start":112},{"file":"SKILL.md","line_end":124,"line_start":120},{"file":"SKILL.md","line_end":133,"line_start":124},{"file":"SKILL.md","line_end":137,"line_start":133},{"file":"SKILL.md","line_end":141,"line_start":137},{"file":"SKILL.md","line_end":145,"line_start":141}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Mutable Remote Instruction Fallback","locations":[{"file":"SKILL.md","line_end":15,"line_start":12},{"file":"SKILL.md","line_end":35,"line_start":33}],"confidence":0.82,"description":"The skill directs agents to use raw cnb.cool fallback URLs for main and sibling skill instructions when local references are unavailable. Mutable remote instructions can change after marketplace review and expand the trusted instruction surface.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Lines 12-15 and 33-35 explicitly provide raw fallback URLs and instruct agents to use them for sibling guidance. The intent is legitimate documentation reuse, but the mutable remote instruction source creates a review bypass risk."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":12,"line_start":12}],"confidence":0.76,"description":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":13,"line_start":13}],"confidence":0.76,"description":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":33,"line_start":33}],"confidence":0.76,"description":"- MySQL SQL management and MCP operations -> `../relational-database-tool/SKILL.md` (standalone fall","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":34,"line_start":34}],"confidence":0.76,"description":"- Web auth/login -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/clo","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":35,"line_start":35}],"confidence":0.76,"description":"- General Web app setup -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/ten","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":148,"audit_model":"codex","audited_at":"2026-07-09T16:48:37.616+00:00","created_at":"2026-07-09T17:30:24.932807+00:00","static_findings":[{"id":"scripts:SKILL.md:87:dynamic-import-expression","file":"SKILL.md","pattern":"Dynamic import() expression","snippet":"- Do not lazy-load the SDK with `import(\"@cloudbase/js-sdk\")` unless the framework absolutely requir","category":"scripts","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If this environment only installed the current skill, start from the CloudBase main entry and use th","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Keep local `references/...` paths for files that ship with the current skill directory. When this fi","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- A browser or Web app must access CloudBase Relational Database through `@cloudbase/js-sdk`.","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- MySQL SQL management and MCP operations -> `../relational-database-tool/SKILL.md` (standalone fall","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Web auth/login -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/clo","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- General Web app setup -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/ten","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Treating `app` itself as the relational database client.","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Route MySQL provisioning/schema work to `relational-database-tool`. If the task says PostgreSQL, C","category":"external_commands","line_end":54,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"After initialization, use `db` with Supabase-style query patterns.","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":67,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":71,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":82,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":87,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Do not lazy-load the SDK with `import(\"@cloudbase/js-sdk\")` unless the framework absolutely requir","category":"external_commands","line_end":88,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Create one shared `db` client and reuse it.","category":"external_commands","line_end":89,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Do not invent unsupported `cloudbase.init()` options.","category":"external_commands","line_end":97,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- you need a canonical shared frontend `db` client","category":"external_commands","line_end":99,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Use `relational-database-tool` instead when","category":"external_commands","line_end":105,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Use `postgresql-development` instead when","category":"external_commands","line_end":107,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- the task says PostgreSQL, CloudBase PG, PG mode, `app.rdb()`, `queryPgDatabase`, `managePgDatabase","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":120,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":124,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":133,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":137,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```javascript","category":"external_commands","line_end":141,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":145,"severity":"medium","line_start":141},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:33:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- MySQL SQL management and MCP operations -> `../relational-database-tool/SKILL.md` (standalone fall","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:SKILL.md:34:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Web auth/login -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/clo","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:SKILL.md:35:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- General Web app setup -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/ten","category":"network","line_end":35,"severity":"low","line_start":35},{"id":"filesystem:SKILL.md:33:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- MySQL SQL management and MCP operations -> `../relational-database-tool/SKILL.md` (standalone fall","category":"filesystem","line_end":33,"severity":"high","line_start":33},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Web auth/login -> `../auth-web/SKILL.md` (standalone fallback: `https://cnb.cool/tencent/cloud/clo","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:SKILL.md:35:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- General Web app setup -> `../web-development/SKILL.md` (standalone fallback: `https://cnb.cool/ten","category":"filesystem","line_end":35,"severity":"high","line_start":35}],"finding_verdicts":[{"id":"scripts:SKILL.md:87:dynamic-import-expression","reason":"The line warns users not to lazy-load the SDK with dynamic import. It is documentation guidance, not executable dynamic code in the skill.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"This is a fenced package installation example for @cloudbase/js-sdk. The skill does not execute the command or build a shell command from input.","verdict":"false_positive","confidence":0.88},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:141:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown inline code or code fence markers. They do not perform Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:12:hardcoded-url","reason":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:SKILL.md:33:hardcoded-url","reason":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:SKILL.md:34:hardcoded-url","reason":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"network:SKILL.md:35:hardcoded-url","reason":"The line provides a raw external URL that the skill directs agents to consult as fallback guidance. This can load mutable instructions outside the packaged skill, although no credential exfiltration is present.","verdict":"confirmed","severity":"low","confidence":0.76},{"id":"filesystem:SKILL.md:33:path-traversal-sequence","reason":"The parent-directory sequence is a fixed Markdown reference to a sibling skill. It is not user-controlled filesystem access or an exploitable path traversal primitive.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","reason":"The parent-directory sequence is a fixed Markdown reference to a sibling skill. It is not user-controlled filesystem access or an exploitable path traversal primitive.","verdict":"false_positive","confidence":0.88},{"id":"filesystem:SKILL.md:35:path-traversal-sequence","reason":"The parent-directory sequence is a fixed Markdown reference to a sibling skill. It is not user-controlled filesystem access or an exploitable path traversal primitive.","verdict":"false_positive","confidence":0.88}],"semantic_findings":[{"title":"Mutable Remote Instruction Fallback","severity":"medium","locations":[{"file":"SKILL.md","line_end":15,"line_start":12},{"file":"SKILL.md","line_end":35,"line_start":33}],"confidence":0.82,"description":"The skill directs agents to use raw cnb.cool fallback URLs for main and sibling skill instructions when local references are unavailable. Mutable remote instructions can change after marketplace review and expand the trusted instruction surface.","confidence_reasoning":"Lines 12-15 and 33-35 explicitly provide raw fallback URLs and instruct agents to use them for sibling guidance. The intent is legitimate documentation reuse, but the mutable remote instruction source creates a review bypass risk."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":5,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}