{"data":{"skill":{"slug":"wshobson-pci-compliance","name":"pci-compliance","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/payment-processing/skills/pci-compliance","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"51afb4de-e4da-42cd-a8d6-3d2052fb2c8c","skill_id":"2e63ec16-d337-42b1-9126-8bb5f7f75326","version":6,"content_hash":"8b9bc2e84021f48f26c47fd154cf0357","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static findings were reviewed against SKILL.md context. The reported command execution, sensitive-file, weak-crypto, reconnaissance, and Windows SAM matches are false positives caused by Markdown fences, PCI terminology, cookie settings, resource names, and defensive examples; no prompt injection or malicious behavior was found. A low-risk documentation concern remains because examples include placeholder payment secrets and card data that should not be copied into production.","remediation":[],"risk_factor_evidence":[],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Illustrative Payment Secrets and Card Data","locations":[{"file":"SKILL.md","line_end":123,"line_start":116},{"file":"SKILL.md","line_end":135,"line_start":135}],"confidence":0.82,"description":"The skill includes sample Stripe key and card values for demonstration. They appear to be placeholders and test data, but users could copy the pattern into production code instead of using managed secret storage and hosted collection.","confidence_reasoning":"The values are clearly shown inside instructional examples, not active code in this package. The risk is documentation misuse rather than credential theft or code execution."},{"title":"Static Command Execution Findings Dismissed","locations":[{"file":"SKILL.md","line_end":97,"line_start":55},{"file":"SKILL.md","line_end":161,"line_start":102},{"file":"SKILL.md","line_end":434,"line_start":396}],"confidence":0.96,"description":"The external command detections correspond to Markdown code fences around Python examples. No Ruby backtick execution, shell execution, subprocess invocation, or user-controlled command construction was found in SKILL.md.","confidence_reasoning":"The flagged locations are fenced documentation examples. There is no executable script file in the reported file structure."},{"title":"Static Sensitive and Reconnaissance Findings Dismissed","locations":[{"file":"SKILL.md","line_end":135,"line_start":127},{"file":"SKILL.md","line_end":154,"line_start":141},{"file":"SKILL.md","line_end":253,"line_start":215},{"file":"SKILL.md","line_end":449,"line_start":441}],"confidence":0.93,"description":"The sensitive-file, Windows SAM, weak-crypto, system reconnaissance, and network reconnaissance alerts are false positives. They match PCI guidance terms, encryption key variables, cookie attributes, resource names, and defensive checklist language.","confidence_reasoning":"The reviewed lines are compliance guidance and safe configuration examples. No evidence found of protected file access, host probing, network scanning, or weak cryptographic implementation."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":467,"audit_model":"codex","audited_at":"2026-07-01T01:19:35.682+00:00","created_at":"2026-07-01T02:22:08.988743+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}