{"data":{"skill":{"slug":"xiaomengbi520-pptx-prep","name":"pptx-prep","icon":"📦","repo":"https://github.com/xiaomengbi520/pptx-prep/tree/main/","status":"approved","author":"xiaomengbi520","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"d5c187dc-96ae-448a-b387-a15b6d7eaeef","skill_id":"c8569678-a46a-4439-8d95-a903f71e7ae1","version":3,"content_hash":"e82f059e20b25e6034ba8bb691be00c7","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static analysis reported many critical and high patterns, but review found most are false positives from manifest field names, examples, markdown code fences, badges, and schema URLs. The real risks are legitimate but elevated workflow behaviors: creating and scanning a materials directory, reading user-provided files, and optionally searching or generating images for missing assets.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":111,"line_start":101},{"file":"SKILL.md","line_end":189,"line_start":181},{"file":"SKILL.md","line_end":244,"line_start":241},{"file":"validate.py","line_end":58,"line_start":28}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":175,"line_start":168},{"file":"README.md","line_end":85,"line_start":80},{"file":"prompts/universal.md","line_end":66,"line_start":65},{"file":"manifest.schema.json","line_end":3,"line_start":2}]},{"factor":"external_commands","evidence":[{"file":"README.md","line_end":49,"line_start":45},{"file":"README.md","line_end":112,"line_start":109}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Filesystem Material Handling","locations":[{"file":"SKILL.md","line_end":111,"line_start":101},{"file":"SKILL.md","line_end":189,"line_start":187},{"file":"SKILL.md","line_end":244,"line_start":241}],"confidence":0.86,"description":"The skill instructs the assistant to create a materials directory, scan user files, auto-match content, and write manifest.yml. This is expected for the skill, but it requires user awareness because files in the project may contain private presentation assets. Verdict: TRUE_POSITIVE for filesystem access risk, not malicious intent.","confidence_reasoning":"The workflow explicitly creates, scans, and records local project files. The behavior is central to the skill and bounded to project materials, so confidence is high for risk presence but not for abuse."},{"title":"Optional Web Search and Image Generation Downloads","locations":[{"file":"SKILL.md","line_end":175,"line_start":168},{"file":"SKILL.md","line_end":183,"line_start":179},{"file":"README.md","line_end":85,"line_start":80}],"confidence":0.82,"description":"For missing presentation materials, the skill can search for real images or generate images, download results into materials, and mark them in the manifest. This introduces network and provenance risk if users choose those options. Verdict: TRUE_POSITIVE for network-enabled workflow risk.","confidence_reasoning":"The instructions clearly call for search or image generation and saving results. The actions require user choice and confirmation, which reduces severity."},{"title":"Local Manifest Validator Reads User-Supplied Files","locations":[{"file":"validate.py","line_end":58,"line_start":28},{"file":"validate.py","line_end":379,"line_start":364}],"confidence":0.72,"description":"validate.py opens a path supplied on the command line and parses YAML or JSON manifests. This is normal validator behavior, but users should run it only on trusted local manifest files. Verdict: TRUE_POSITIVE for file read capability, low evidence of exploitation.","confidence_reasoning":"The script directly reads the requested file and does not perform network calls or command execution. The risk is limited to local file handling and malformed input parsing."}],"low_findings":[{"title":"Weak Cryptography Flags Are False Positives","locations":[{"file":"manifest.schema.json","line_end":74,"line_start":37},{"file":"SKILL.md","line_end":214,"line_start":191},{"file":"examples/scenario-pitch/manifest.yml","line_end":78,"line_start":71}],"confidence":0.91,"description":"The high-severity weak cryptography hits occur on manifest and prompt terms such as status, source, confidence, path, and examples. I found no hashing, encryption, signing, or weak crypto API use in the reviewed files. Verdict: FALSE_POSITIVE.","confidence_reasoning":"The cited contexts define presentation material metadata rather than cryptographic operations. Static line hits align with schema and YAML fields, not crypto code."},{"title":"Ruby Backtick Execution Flags Are Markdown False Positives","locations":[{"file":"README.md","line_end":49,"line_start":45},{"file":"README.md","line_end":112,"line_start":109},{"file":"PLACEHOLDER_SPEC.md","line_end":44,"line_start":33},{"file":"prompts/universal.md","line_end":31,"line_start":21}],"confidence":0.88,"description":"The external command findings are mostly markdown code fences, inline code, and usage examples. The skill does not contain Ruby code or shell backtick execution logic. Verdict: FALSE_POSITIVE for Ruby execution.","confidence_reasoning":"The cited files are documentation or prompt templates. The visible content is fenced examples and literal paths, not executable Ruby backticks."},{"title":"Hardcoded URL Findings Are Documentation Links","locations":[{"file":"manifest.schema.json","line_end":3,"line_start":2},{"file":"README.md","line_end":9,"line_start":7},{"file":"README_CN.md","line_end":9,"line_start":7}],"confidence":0.84,"description":"The hardcoded URL findings are schema identifiers and README badge image URLs. They do not perform runtime network requests by themselves. Verdict: FALSE_POSITIVE for active network behavior, with minor documentation tracking risk for badge images.","confidence_reasoning":"The URLs are static metadata or badge references. They are not fetched by skill code unless a renderer loads README images."},{"title":"Critical Dangerous Combination Not Confirmed","locations":[{"file":"SKILL.md","line_end":183,"line_start":168},{"file":"README.md","line_end":49,"line_start":45},{"file":"validate.py","line_end":58,"line_start":28}],"confidence":0.79,"description":"The scanner reported code execution plus network plus credential access, but review found no credential harvesting or exfiltration evidence in the cited files. Network and filesystem behavior exist, but they are presentation-material workflow features. Verdict: FALSE_POSITIVE for confirmed malicious combination.","confidence_reasoning":"I found concrete workflow use of files and optional network search, but no credential access semantics. Confidence is high enough to dismiss the critical claim while retaining medium risk."}],"dangerous_patterns":[],"files_scanned":15,"total_lines":1783,"audit_model":"codex","audited_at":"2026-07-01T01:38:34.298+00:00","created_at":"2026-07-07T02:38:46.034827+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":4,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}