{"data":{"skill":{"slug":"tencentcloudbase-spec-workflow","name":"spec-workflow","icon":"📦","repo":"https://github.com/tencentcloudbase/skills/tree/main/skills/spec-workflow","status":"approved","author":"tencentcloudbase","authorVersion":"2.23.8","skillstoreRevision":1},"audit":{"id":"87aab41e-e2c5-4e89-a585-bba8d1dcb5d9","skill_id":"3ac4bdf5-41ef-449f-b3a8-f5cadc3869d3","version":2,"content_hash":"v3:24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec:542b926c78d5b2acce31d7e94ef4c7da0c9e81027deff8d31ec9d460c1d29eba:ddcef5072674cd77b145b2a38b239a89819d678103875c9a70a88129f4591255:736b696c6c732f74656e63656e74636c6f7564626173652f737065632d776f726b666c6f77:3fca07cacea9c059d3bcd59657ff61bb","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All static findings appear to be false positives caused by Markdown code fences, inline code, literal URLs, and sibling skill references. No evidence of command execution, arbitrary filesystem access, network exfiltration, prompt injection, or malicious intent was found in SKILL.md.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":15,"line_start":15},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":101,"line_start":99},{"file":"SKILL.md","line_end":105,"line_start":101},{"file":"SKILL.md","line_end":107,"line_start":105},{"file":"SKILL.md","line_end":111,"line_start":107},{"file":"SKILL.md","line_end":122,"line_start":111},{"file":"SKILL.md","line_end":133,"line_start":122},{"file":"SKILL.md","line_end":140,"line_start":133},{"file":"SKILL.md","line_end":156,"line_start":140},{"file":"SKILL.md","line_end":162,"line_start":156},{"file":"SKILL.md","line_end":163,"line_start":162},{"file":"SKILL.md","line_end":164,"line_start":163}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":34,"line_start":34},{"file":"SKILL.md","line_end":35,"line_start":35}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":165,"audit_model":"codex","audited_at":"2026-07-09T16:52:41.997+00:00","created_at":"2026-07-15T09:20:57.764692+00:00","static_findings":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If this environment only installed the current skill, start from the CloudBase main entry and use th","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Keep local `references/...` paths for files that ship with the current skill directory. When this fi","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Frontend page or visual design work -> `../ui-design/SKILL.md` (standalone fallback: `https://cnb.","category":"external_commands","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Advanced data-model work -> `../data-model-creation/SKILL.md` (standalone fallback: `https://cnb.c","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create `specs/<spec_name>/requirements.md`.","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":101,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":105,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":107,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":111,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create `specs/<spec_name>/design.md`.","category":"external_commands","line_end":122,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create `specs/<spec_name>/tasks.md`.","category":"external_commands","line_end":133,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":140,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":156,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Pull in `ui-design` early when the change includes end-user pages or visual decisions.","category":"external_commands","line_end":162,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `requirements.md` -> problem, scope, user stories, EARS acceptance criteria","category":"external_commands","line_end":163,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `design.md` -> architecture, technical approach, data/API/security/test notes","category":"external_commands","line_end":164,"severity":"medium","line_start":163},{"id":"network:SKILL.md:3:python-http-libraries","file":"SKILL.md","pattern":"Python HTTP libraries","snippet":"description: Use when medium-to-large changes need explicit requirements, technical design, and task","category":"network","line_end":3,"severity":"low","line_start":3},{"id":"network:SKILL.md:12:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- CloudBase main entry: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/main/sk","category":"network","line_end":12,"severity":"low","line_start":12},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Current skill raw source: `https://cnb.cool/tencent/cloud/cloudbase/cloudbase-skills/-/git/raw/mai","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:34:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Frontend page or visual design work -> `../ui-design/SKILL.md` (standalone fallback: `https://cnb.","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:SKILL.md:35:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Advanced data-model work -> `../data-model-creation/SKILL.md` (standalone fallback: `https://cnb.c","category":"network","line_end":35,"severity":"low","line_start":35},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Frontend page or visual design work -> `../ui-design/SKILL.md` (standalone fallback: `https://cnb.","category":"filesystem","line_end":34,"severity":"high","line_start":34},{"id":"filesystem:SKILL.md:35:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"- Advanced data-model work -> `../data-model-creation/SKILL.md` (standalone fallback: `https://cnb.c","category":"filesystem","line_end":35,"severity":"high","line_start":35},{"id":"blocker:SKILL.md:118:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Use Mermaid only when a diagram materially improves clarity","category":"blocker","line_end":118,"severity":"low","line_start":118}],"finding_verdicts":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"The backticks wrap a literal documentation path in Markdown. There is no shell command, subprocess call, or dynamic execution behavior.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The line documents a published skill URL or sibling skill reference for context. No data is sent, and there is no executable network call in the skill.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"The line documents a published skill URL or sibling skill reference for context. No data is sent, and there is no executable network call in the skill.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The backticks mark literal skill names and paths in prose. The line explains documentation resolution and contains no executable command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The backticks mark a sibling Markdown path and fallback URL. The instruction is to read reference documentation, not execute a command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The backticks mark a sibling Markdown path and fallback URL. The instruction is to read reference documentation, not execute a command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticks wrap the target document path for requirements output. Creating a project spec file is expected workflow behavior, not external command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The line contains Markdown inline code or a fenced example, not shell backtick execution. It does not instruct execution of external commands or process user input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The line contains Markdown inline code or a fenced example, not shell backtick execution. It does not instruct execution of external commands or process user input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The line contains Markdown inline code or a fenced example, not shell backtick execution. It does not instruct execution of external commands or process user input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The line contains Markdown inline code or a fenced example, not shell backtick execution. It does not instruct execution of external commands or process user input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The backticks wrap the target design document path. This is normal file naming guidance and does not invoke an external command.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The backticks wrap the target task document path. This is normal file naming guidance and does not invoke an external command.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The line contains Markdown inline code or a fenced example, not shell backtick execution. It does not instruct execution of external commands or process user input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The line contains Markdown inline code or a fenced example, not shell backtick execution. It does not instruct execution of external commands or process user input.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The backticks identify a sibling skill by name in prose. It does not call a shell or run any external process.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The backticks identify an expected output filename. The line defines documentation output and contains no command execution.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The backticks identify an expected output filename. The line defines documentation output and contains no command execution.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:3:python-http-libraries","reason":"Line 3 is frontmatter text describing requirements and technical design. It does not import Python HTTP libraries or perform any network operation.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:12:hardcoded-url","reason":"The line documents a published skill URL or sibling skill reference for context. No data is sent, and there is no executable network call in the skill.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The line documents a published skill URL or sibling skill reference for context. No data is sent, and there is no executable network call in the skill.","verdict":"false_positive","confidence":0.94},{"id":"network:SKILL.md:34:hardcoded-url","reason":"The line documents a published skill URL or sibling skill reference for context. No data is sent, and there is no executable network call in the skill.","verdict":"false_positive","confidence":0.93},{"id":"network:SKILL.md:35:hardcoded-url","reason":"The line documents a published skill URL or sibling skill reference for context. No data is sent, and there is no executable network call in the skill.","verdict":"false_positive","confidence":0.93},{"id":"filesystem:SKILL.md:34:path-traversal-sequence","reason":"The ../ path is a static reference to sibling skill documentation, not arbitrary path traversal. It is not user-controlled and does not direct broad filesystem access.","verdict":"false_positive","confidence":0.9},{"id":"filesystem:SKILL.md:35:path-traversal-sequence","reason":"The ../ path is a static reference to sibling skill documentation, not arbitrary path traversal. It is not user-controlled and does not direct broad filesystem access.","verdict":"false_positive","confidence":0.9},{"id":"blocker:SKILL.md:118:system-reconnaissance","reason":"The line recommends Mermaid diagrams only when useful. The word system appears in design guidance and does not request host or network reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec","subject_content_hash":"542b926c78d5b2acce31d7e94ef4c7da0c9e81027deff8d31ec9d460c1d29eba","subject_tree_hash":"ddcef5072674cd77b145b2a38b239a89819d678103875c9a70a88129f4591255","subject_plugin_path":"skills/tencentcloudbase/spec-workflow","audit_payload_hash":"3fca07cacea9c059d3bcd59657ff61bb","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec","contentHash":"542b926c78d5b2acce31d7e94ef4c7da0c9e81027deff8d31ec9d460c1d29eba","treeHash":"ddcef5072674cd77b145b2a38b239a89819d678103875c9a70a88129f4591255","pluginPath":"skills/tencentcloudbase/spec-workflow","auditPayloadHash":"3fca07cacea9c059d3bcd59657ff61bb"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}