{"data":{"skill":{"slug":"wshobson-rag-implementation","name":"rag-implementation","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/llm-application-dev/skills/rag-implementation","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"475d6174-dbf2-4df3-927a-f4212c6613c4","skill_id":"2a4579d9-faa6-4311-a230-57c20b4c6364","version":5,"content_hash":"7b69ca9f28b2575fe642ead27a5ab1a8","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported many high-risk patterns, but review found they are Markdown documentation examples rather than executable skill code. The Ruby backtick findings are false positives caused by fenced Python code blocks. The remaining concerns are low-risk instructional examples that mention a placeholder API key and a localhost vector database URL.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":236,"line_start":236}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Markdown Code Fences Misclassified as Shell Execution","locations":[{"file":"SKILL.md","line_end":98,"line_start":62},{"file":"SKILL.md","line_end":118,"line_start":103},{"file":"SKILL.md","line_end":132,"line_start":121},{"file":"SKILL.md","line_end":148,"line_start":135},{"file":"SKILL.md","line_end":168,"line_start":151},{"file":"SKILL.md","line_end":182,"line_start":173},{"file":"SKILL.md","line_end":192,"line_start":185},{"file":"SKILL.md","line_end":202,"line_start":195},{"file":"SKILL.md","line_end":215,"line_start":205},{"file":"SKILL.md","line_end":229,"line_start":220},{"file":"SKILL.md","line_end":239,"line_start":232},{"file":"SKILL.md","line_end":250,"line_start":242},{"file":"SKILL.md","line_end":272,"line_start":255},{"file":"SKILL.md","line_end":283,"line_start":275},{"file":"SKILL.md","line_end":300,"line_start":286},{"file":"SKILL.md","line_end":314,"line_start":305},{"file":"SKILL.md","line_end":326,"line_start":317},{"file":"SKILL.md","line_end":339,"line_start":329},{"file":"SKILL.md","line_end":373,"line_start":343}],"confidence":0.96,"description":"Static analysis flagged many Ruby or shell backtick executions, but the cited regions are fenced Python examples in SKILL.md. No executable script, shell invocation, or command injection path was found in the skill package.","confidence_reasoning":"The cited lines are visibly Markdown fenced code examples. The skill contains no separate executable file or instruction to run hidden shell commands."},{"title":"Placeholder API Key in Documentation Example","locations":[{"file":"SKILL.md","line_end":224,"line_start":224}],"confidence":0.88,"description":"The Pinecone example includes api_key=\"your-api-key\" as a placeholder. This is not credential theft or environment access, but users should replace it with secure secret handling when implementing the example.","confidence_reasoning":"The value is an obvious placeholder inside a documentation snippet. The risk is limited to copy-paste security hygiene rather than malicious skill behavior."},{"title":"Localhost Network URL in Vector Store Example","locations":[{"file":"SKILL.md","line_end":236,"line_start":236}],"confidence":0.91,"description":"The Weaviate example connects to http://localhost:8080. This is a local service configuration example, not an external exfiltration endpoint or hidden network call.","confidence_reasoning":"The URL points to localhost and appears in a clearly labeled Weaviate configuration example. No evidence of data exfiltration was found."},{"title":"Static Blocker Terms Are Contextual False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":391,"line_start":391},{"file":"SKILL.md","line_end":400,"line_start":400}],"confidence":0.93,"description":"The weak cryptography and reconnaissance blocker alerts map to ordinary RAG terminology and retrieval strategy text. No cryptographic operation, system probing, prompt injection attempt, or privilege escalation instruction was found.","confidence_reasoning":"Manual review of the cited lines found domain vocabulary and headings only. There is no semantic evidence of cryptographic misuse or reconnaissance behavior."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":404,"audit_model":"codex","audited_at":"2026-07-01T00:31:40.137+00:00","created_at":"2026-07-01T02:22:10.198856+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":1,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}