{"data":{"skill":{"slug":"wshobson-brand-landingpage","name":"brand-landingpage","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/brand-landingpage/skills/brand-landingpage/","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"23371cc1-eb72-4b16-b4de-2151e6293808","skill_id":"4b34e3dc-2f47-4461-982d-d46ff8550384","version":3,"content_hash":"0aabdcaae6e4cffc4200faaf5ad3a019","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported many high-severity patterns, but review found most were Markdown false positives from backticked terms, color hex values, and examples. The confirmed risks are legitimate workflow actions: installing or using the Stitch SDK, checking an API key environment variable, making external Stitch calls, writing project files, opening local HTML in a browser, and creating a zip bundle.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":36,"line_start":31},{"file":"SKILL.md","line_end":249,"line_start":248},{"file":"references/stitch-architecture.md","line_end":14,"line_start":13}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":169,"line_start":167},{"file":"SKILL.md","line_end":241,"line_start":236}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":36,"line_start":31}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":34,"line_start":32},{"file":"SKILL.md","line_end":168,"line_start":168},{"file":"SKILL.md","line_end":241,"line_start":241}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"External Stitch SDK and Network Workflow","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":36,"line_start":31},{"file":"SKILL.md","line_end":249,"line_start":248},{"file":"references/stitch-architecture.md","line_end":14,"line_start":13}],"confidence":0.82,"description":"The skill instructs the agent to verify SDK installation, make a minimal authenticated SDK call, and rely on Stitch documentation and generated download URLs. This is expected for the skill, but it requires third-party network access and should be disclosed to users.","confidence_reasoning":"The workflow clearly depends on an external SDK, documentation, authentication check, and generated download URLs. No evidence shows credential exfiltration, so the risk is operational rather than malicious."},{"title":"Environment Variable Check for API Key","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":36,"line_start":31}],"confidence":0.78,"description":"The skill tells the agent to verify that the Stitch API key environment variable is set and to help the user export it if missing. It also instructs the agent not to display or echo the key, which reduces but does not remove secret-handling risk.","confidence_reasoning":"The file explicitly references checking an API key environment variable and user export flow. The same section includes a protective instruction not to echo the key, so this is a managed medium risk."},{"title":"Filesystem Writes, Browser Opening, and Zip Creation","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":169,"line_start":167},{"file":"SKILL.md","line_end":241,"line_start":236}],"confidence":0.8,"description":"The skill writes state, generated HTML, user-provided assets, design documentation, and deployment bundles. It also opens saved HTML through OS browser commands and creates a zip archive, which are legitimate delivery steps but can affect the local workspace.","confidence_reasoning":"The documented workflow intentionally creates and copies files, opens local HTML, and runs zip packaging. These actions are scoped to generated project artifacts and do not show malicious intent."}],"low_findings":[{"title":"Markdown Backtick Command Alerts Are Mostly False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"references/state-and-pitfalls.md","line_end":36,"line_start":5},{"file":"references/stitch-architecture.md","line_end":254,"line_start":232}],"confidence":0.94,"description":"Many external command findings come from Markdown inline code, code fences, tool names, enum names, and template examples. They describe the workflow and API shapes rather than executable code embedded in the skill.","confidence_reasoning":"The cited lines are Markdown documentation and examples, not script files or runtime code. The only real command usage is separately captured in the medium findings."},{"title":"Weak Cryptography Alerts Are Color and Identifier False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"references/interview-framework.md","line_end":137,"line_start":123},{"file":"references/stitch-architecture.md","line_end":126,"line_start":115},{"file":"references/state-and-pitfalls.md","line_end":31,"line_start":20}],"confidence":0.96,"description":"The weak-cryptography alerts map to color hex values, typography names, state fields, and design-system identifiers. No evidence found of cryptographic operations or weak crypto algorithms being used.","confidence_reasoning":"The cited context is color mapping and metadata schema content. There is no hashing, encryption, signing, or password-storage logic in these files."},{"title":"C2 and SAM Keyword Alerts Are Scanner Noise","verdict":"FALSE_POSITIVE","locations":[{"file":"references/interview-framework.md","line_end":130,"line_start":130},{"file":"references/stitch-architecture.md","line_end":119,"line_start":119},{"file":"SKILL.md","line_end":62,"line_start":62}],"confidence":0.91,"description":"The C2 and Windows SAM alerts appear to be substring matches inside harmless design documentation. No evidence found of command-and-control behavior, system database access, or credential dumping intent.","confidence_reasoning":"The referenced lines are color rows or a workflow diagram line. They do not contain code, URLs for control servers, or operating-system credential paths."}],"dangerous_patterns":[],"files_scanned":4,"total_lines":841,"audit_model":"codex","audited_at":"2026-06-30T22:16:09.819+00:00","created_at":"2026-06-30T23:49:21.559319+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":3,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}