{"data":{"skill":{"slug":"wshobson-python-performance-optimization","name":"python-performance-optimization","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/python-development/skills/python-performance-optimization","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"247143f6-729d-4516-b004-e2cc8dce9867","skill_id":"85ef3fbd-bab4-4686-9e9d-aeda9c9eb8ce","version":6,"content_hash":"d5f9350fe3a677c7c8df873eb7a86244","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static analysis reported many command-execution alerts, but review shows they are Markdown code fences and example profiler commands, not executable skill code. The skill is documentation-only, with low residual risk from copied examples that run local profilers, open local files, or call httpbin.org for I/O benchmarking.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":121,"line_start":113},{"file":"SKILL.md","line_end":143,"line_start":142},{"file":"SKILL.md","line_end":195,"line_start":194},{"file":"SKILL.md","line_end":213,"line_start":200},{"file":"SKILL.md","line_end":821,"line_start":821}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":589,"line_start":560}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":666,"line_start":666},{"file":"SKILL.md","line_end":739,"line_start":730}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Example Commands Profile Local Processes","locations":[{"file":"SKILL.md","line_end":213,"line_start":200}],"confidence":0.82,"description":"The py-spy examples inspect a local process by PID and can expose stack information if a user runs them against sensitive production services. This is legitimate performance tooling, and no evidence shows the skill executes these commands automatically.","confidence_reasoning":"The line-numbered context shows explicit py-spy commands against a PID. The risk depends on a user manually running the documented command, so severity remains low."},{"title":"Example HTTP Benchmark Uses External Service","locations":[{"file":"SKILL.md","line_end":589,"line_start":560}],"confidence":0.9,"description":"The async I/O example imports requests and aiohttp and calls https://httpbin.org/delay/1. This is a benign timing demonstration, but copied code would make outbound network requests.","confidence_reasoning":"The URLs and HTTP client calls are visible in the referenced lines. They target a public test endpoint and do not include credentials or exfiltration logic."},{"title":"Examples Open Local Files and Databases","locations":[{"file":"SKILL.md","line_end":666,"line_start":666},{"file":"SKILL.md","line_end":739,"line_start":730}],"confidence":0.78,"description":"The SQLite and iterator examples open example.db or a caller-provided filename. This is normal optimization guidance, but users should test with non-sensitive data.","confidence_reasoning":"The examples clearly demonstrate local file and database access. They are not hidden behavior because SKILL.md is the only file and contains documentation examples only."},{"title":"Static Command Alerts Are Markdown False Positives","locations":[{"file":"SKILL.md","line_end":69,"line_start":47},{"file":"SKILL.md","line_end":125,"line_start":75},{"file":"SKILL.md","line_end":822,"line_start":782}],"confidence":0.96,"description":"The many Ruby or shell backtick findings correspond to Markdown fenced code blocks and sample snippets. No standalone script, installer, or automatic command runner was found in the skill package.","confidence_reasoning":"Line-numbered review shows fenced code examples rather than executable Ruby backticks. The package contains only SKILL.md, so there is no execution surface outside user-copied examples."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":870,"audit_model":"codex","audited_at":"2026-07-01T00:25:34.808+00:00","created_at":"2026-07-07T02:39:01.070522+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}