{"data":{"skill":{"slug":"wshobson-mtls-configuration","name":"mtls-configuration","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/cloud-infrastructure/skills/mtls-configuration","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"7a1c3cc9-8f40-4013-8ede-c774deac11ac","skill_id":"8977ddde-8687-42bc-b2df-9e4670e74dbd","version":5,"content_hash":"c75911880cafe32fd62d94ca87b2183a","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The static analyzer flagged many Markdown code fences as Ruby backtick execution, which is a false positive for this documentation-only skill. Real risk remains because several copy-pastable examples permit, disable, or bypass mTLS and include certificate file paths that require careful secret handling.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":324,"line_start":293}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":130,"line_start":118},{"file":"SKILL.md","line_end":198,"line_start":198},{"file":"SKILL.md","line_end":347,"line_start":344}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":136,"line_start":122},{"file":"SKILL.md","line_end":160,"line_start":159},{"file":"SKILL.md","line_end":232,"line_start":231},{"file":"SKILL.md","line_end":259,"line_start":253}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Copy-pastable mTLS exceptions can weaken production service protection","locations":[{"file":"SKILL.md","line_end":77,"line_start":69},{"file":"SKILL.md","line_end":95,"line_start":91},{"file":"SKILL.md","line_end":288,"line_start":282}],"confidence":0.88,"description":"The skill includes examples for PERMISSIVE mode, a disabled metrics port, and skipped Linkerd outbound ports. These are legitimate migration and exception patterns, but they can reduce service-to-service authentication if copied without strict scope and review.","confidence_reasoning":"The examples explicitly configure weaker or bypass behavior. The surrounding text presents them as templates, so misuse is plausible even though there is no malicious intent."},{"title":"External TLS example does not use mutual authentication","locations":[{"file":"SKILL.md","line_end":122,"line_start":112}],"confidence":0.84,"description":"The external service example uses SIMPLE TLS with only a CA certificate. This may be appropriate for some outbound calls, but it does not provide mTLS client authentication and may conflict with the skill's mTLS focus.","confidence_reasoning":"The configuration clearly uses mode SIMPLE, followed by a separate MUTUAL example. This is a confirmed weaker pattern, but it can be legitimate for non-mTLS external services."}],"low_findings":[{"title":"Markdown code fences misclassified as Ruby backtick execution","locations":[{"file":"SKILL.md","line_end":37,"line_start":23},{"file":"SKILL.md","line_end":52,"line_start":41},{"file":"SKILL.md","line_end":325,"line_start":58}],"confidence":0.98,"description":"The static external command findings at the template and diagram sections are false positives. They are Markdown fences that contain diagrams, YAML, or shell examples, not executable Ruby code.","confidence_reasoning":"Line-number review shows fenced Markdown blocks, not Ruby execution. No file contains runnable Ruby code or a command execution wrapper."},{"title":"Certificate and private key paths are placeholders, not embedded secrets","locations":[{"file":"SKILL.md","line_end":136,"line_start":122},{"file":"SKILL.md","line_end":160,"line_start":159},{"file":"SKILL.md","line_end":232,"line_start":231}],"confidence":0.93,"description":"The skill references certificate paths and placeholder encoded certificate material. No real private key or certificate value is present, but users must avoid committing real key material when adapting the examples.","confidence_reasoning":"The referenced values are file paths or angle-bracket placeholders. This confirms the static sensitive-data findings are not leaked credentials."},{"title":"Hardcoded URLs and IP address are documentation references or bind examples","locations":[{"file":"SKILL.md","line_end":198,"line_start":198},{"file":"SKILL.md","line_end":347,"line_start":344}],"confidence":0.96,"description":"The URLs point to public documentation resources, and the 0.0.0.0 value appears in a SPIRE server bind address example. There is no evidence of data exfiltration or unauthorized network access.","confidence_reasoning":"The hardcoded network indicators are visible documentation or configuration examples. No code sends data to these URLs or addresses."},{"title":"Weak cryptography findings are terminology and Kubernetes resource matches","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":126,"line_start":98},{"file":"SKILL.md","line_end":316,"line_start":315}],"confidence":0.91,"description":"The static weak-cryptography hits correspond to mTLS description text and Kubernetes DestinationRule examples. I found no MD5, SHA-1, DES, RC4, or other weak cryptographic primitive in the skill.","confidence_reasoning":"Manual review found security configuration terms rather than weak algorithms. The finding is likely caused by broad keyword matching."}],"dangerous_patterns":[{"title":"mTLS bypass or downgrade configuration examples","locations":[{"file":"SKILL.md","line_end":77,"line_start":69},{"file":"SKILL.md","line_end":95,"line_start":91},{"file":"SKILL.md","line_end":288,"line_start":282}],"confidence":0.88,"description":"Examples include PERMISSIVE mode, DISABLE on a port, and skip-outbound-ports. These patterns should be documented as migration-only or exception-only settings.","confidence_reasoning":"The risky configuration modes are explicit in the templates. The risk depends on how users apply them."},{"title":"Private key handling in reusable templates","locations":[{"file":"SKILL.md","line_end":160,"line_start":134},{"file":"SKILL.md","line_end":232,"line_start":229}],"confidence":0.82,"description":"Reusable templates reference private key files and TLS secrets. This is expected for mTLS, but it requires secret-manager integration and strict access controls.","confidence_reasoning":"The skill necessarily handles certificate paths and key references. The content uses placeholders, so the pattern is risky but not evidence of leakage."}],"files_scanned":1,"total_lines":348,"audit_model":"codex","audited_at":"2026-07-01T00:54:26.79+00:00","created_at":"2026-07-01T02:22:07.46581+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}