{"data":{"skill":{"slug":"wshobson-event-store-design","name":"event-store-design","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/backend-development/skills/event-store-design","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"dfb5d1ed-86bd-47d9-971b-839219f5180e","skill_id":"9343bee5-75b2-4605-a263-ec40f327f675","version":5,"content_hash":"a47e378f768f5e78307ee16b8fca4b13","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"AI review downgraded the static risk score after checking SKILL.md. The backtick, weak cryptography, reconnaissance, and fetch detections are false positives from markdown fences, documentation text, schema examples, database calls, and public reference links. One medium issue remains because the EventStoreDB example disables TLS for a localhost URI, which needs a publication warning for production use.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":296,"line_start":296},{"file":"SKILL.md","line_end":368,"line_start":367},{"file":"SKILL.md","line_end":435,"line_start":433}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Example EventStoreDB Connection Disables TLS","locations":[{"file":"SKILL.md","line_end":296,"line_start":296}],"confidence":0.74,"description":"The EventStoreDB template shows a connection URI with tls=false. This is reasonable for a local development endpoint, but users could copy it into production and send event data over an unencrypted connection.","confidence_reasoning":"The insecure setting is explicit, but the URI targets localhost. The risk depends on whether users adapt the example for non-local deployments without changing TLS settings."}],"low_findings":[{"title":"External Command Detections Are Markdown Fence False Positives","locations":[{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":112,"line_start":112},{"file":"SKILL.md","line_end":287,"line_start":287},{"file":"SKILL.md","line_end":291,"line_start":291},{"file":"SKILL.md","line_end":354,"line_start":354},{"file":"SKILL.md","line_end":358,"line_start":358},{"file":"SKILL.md","line_end":414,"line_start":414}],"confidence":0.97,"description":"Verdict: FALSE_POSITIVE. The Ruby/shell backtick detections point to markdown code fence delimiters around diagrams and examples, not executable shell commands. No evidence found of command execution logic in SKILL.md.","confidence_reasoning":"The flagged lines are markdown fence delimiters or boundaries of fenced examples. They are not interpreted as Ruby backticks or shell execution by the skill runtime."},{"title":"Network Detections Are Database Examples And Documentation Links","locations":[{"file":"SKILL.md","line_end":197,"line_start":197},{"file":"SKILL.md","line_end":217,"line_start":217},{"file":"SKILL.md","line_end":433,"line_start":433},{"file":"SKILL.md","line_end":434,"line_start":434},{"file":"SKILL.md","line_end":435,"line_start":435}],"confidence":0.92,"description":"Verdict: FALSE_POSITIVE for exfiltration. The fetch detections are asyncpg database reads inside an illustrative Python template, and the URLs are public documentation resources. No evidence found of hidden outbound requests, credential transfer, or unauthorized data collection.","confidence_reasoning":"The method calls are SQL client calls on a database connection, not browser fetch or HTTP exfiltration. The hardcoded URLs are visible reference links at the end of the document."},{"title":"Weak Cryptography Detections Are Text Substring False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":2},{"file":"SKILL.md","line_end":8,"line_start":6},{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":43,"line_start":43}],"confidence":0.95,"description":"Verdict: FALSE_POSITIVE. The weak cryptography detections occur in ordinary documentation text such as the skill name, description, headings, and table labels. No cryptographic implementation or weak algorithm usage was found in the reviewed file.","confidence_reasoning":"The flagged text is natural language related to design and descriptions. There is no crypto API, cipher selection, hashing function, or key handling code at these locations."},{"title":"Reconnaissance Detections Are Schema And Example Identifiers","locations":[{"file":"SKILL.md","line_end":69,"line_start":68},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":150,"line_start":149},{"file":"SKILL.md","line_end":161,"line_start":160},{"file":"SKILL.md","line_end":202,"line_start":202},{"file":"SKILL.md","line_end":245,"line_start":243},{"file":"SKILL.md","line_end":363,"line_start":363}],"confidence":0.93,"description":"Verdict: FALSE_POSITIVE. The system reconnaissance detections map to SQL column names, index names, UUID imports, and query placeholders in event store examples. No evidence found of host enumeration, process inspection, or environment reconnaissance behavior.","confidence_reasoning":"The surrounding context shows data model fields and parameterized database examples. None of the locations include commands that inspect the local system or collect host metadata."}],"dangerous_patterns":[{"title":"Example EventStoreDB Connection Disables TLS","locations":[{"file":"SKILL.md","line_end":296,"line_start":296}],"confidence":0.74,"description":"The EventStoreDB template shows a connection URI with tls=false. This is reasonable for a local development endpoint, but users could copy it into production and send event data over an unencrypted connection.","confidence_reasoning":"The insecure setting is explicit, but the URI targets localhost. The risk depends on whether users adapt the example for non-local deployments without changing TLS settings."}],"files_scanned":1,"total_lines":436,"audit_model":"codex","audited_at":"2026-07-01T00:33:11.597+00:00","created_at":"2026-07-01T02:22:03.186042+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}