{"data":{"skill":{"slug":"yamadashy-agent-memory","name":"agent-memory","icon":"📦","repo":"https://github.com/yamadashy/repomix/tree/main/.claude/skills/agent-memory","status":"approved","author":"yamadashy","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"f1d7827c-9922-4155-810c-3fa97b92d17d","skill_id":"d4df10de-5f96-4f70-a64a-51ead25119a2","version":8,"content_hash":"v3:64ca8af0f54a325752f08bd54e52151061ea659a:bc67ae88a3019aedfb577eb1fd34295f884166e82ca40633901c56859d610af7:0579a70cc1a607c0a80213560ccc4b393af1e9053bc9da8fe57bad26f3cbd41e:736b696c6c732f79616d6164617368792f6167656e742d6d656d6f7279:6d332e338365b71d75342d540d15b2af","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 19 static findings are false positives. The reported shell-execution findings identify Markdown code fences and inline code, not executed commands. The documented commands operate only on the skill's local memory directory, and no prompt injection, credential access, network activity, or data-exfiltration intent was found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":45,"line_start":37},{"file":"SKILL.md","line_end":51,"line_start":45},{"file":"SKILL.md","line_end":54,"line_start":51},{"file":"SKILL.md","line_end":59,"line_start":54},{"file":"SKILL.md","line_end":62,"line_start":59},{"file":"SKILL.md","line_end":70,"line_start":62},{"file":"SKILL.md","line_end":76,"line_start":70},{"file":"SKILL.md","line_end":93,"line_start":76},{"file":"SKILL.md","line_end":95,"line_start":93},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":105,"line_start":103},{"file":"SKILL.md","line_end":118,"line_start":105},{"file":"SKILL.md","line_end":122,"line_start":118},{"file":"SKILL.md","line_end":124,"line_start":122},{"file":"SKILL.md","line_end":128,"line_start":124}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":127,"line_start":127}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":144,"audit_model":"claude","audited_at":"2026-07-21T08:30:58.01+00:00","created_at":"2026-07-21T08:49:36.924633+00:00","static_findings":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Location:** `.claude/skills/agent-memory/memories/`","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":45,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":51,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"All memories must include frontmatter with a `summary` field. The summary should be concise enough t","category":"external_commands","line_end":54,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":59,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":62,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":70,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":76,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":93,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":95,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Note:** Memory files are gitignored, so use `--no-ignore` and `--hidden` flags with ripgrep.","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Write file with required frontmatter (use `date +%Y-%m-%d` for current date)","category":"external_commands","line_end":105,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":118,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":122,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Update**: When information changes, update the content and add `updated` field to frontmatter","category":"external_commands","line_end":124,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":128,"severity":"medium","line_start":124},{"id":"filesystem:SKILL.md:127:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"rmdir .claude/skills/agent-memory/memories/category-name/ 2>/dev/null || true","category":"filesystem","line_end":127,"severity":"low","line_start":127},{"id":"blocker:SKILL.md:3:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"description: \"Use this skill when the user asks to save, remember, recall, or organize memories. Tri","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"blocker:SKILL.md:107:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"# Note: Check if file exists before writing to avoid accidental overwrites","category":"blocker","line_end":107,"severity":"low","line_start":107}],"finding_verdicts":[{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"This is a Markdown inline-code path naming the local memory directory. It does not execute Ruby or a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The finding starts a fenced text example. Markdown fences are documentation syntax, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"This line closes a Markdown code fence. It contains no executable instruction or shell invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The backticks format the frontmatter field name in prose. No command is run or constructed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"This is the opening delimiter for a YAML documentation example. It is not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"This line only closes a YAML Markdown code fence. It has no operational behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"This is an opening Markdown fence for an optional YAML example. It does not invoke a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"This is a closing Markdown fence. It is documentation syntax without executable content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"This opens a bash example that documents local listing and search commands. The fence itself does not execute anything.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"This closes the bash example. It is not a shell execution primitive.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The backticks format ripgrep flags in explanatory prose. They do not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The inline code documents a date command for a frontmatter value. It does not contain an execution mechanism.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"This opens a Markdown bash example for creating a local memory file. The delimiter does not execute the example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"This line closes a Markdown code block. It has no executable behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The backticks merely highlight the updated frontmatter field in prose. No command execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"This starts a Markdown bash example for deleting a local memory. A code fence is not command execution.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:127:standard-device-file-access","reason":"The documented rmdir command targets only an empty category under the skill's memory directory. Error output is suppressed only to make empty-directory cleanup idempotent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:3:system-reconnaissance","reason":"The description lists user requests that trigger this memory-management skill. It does not collect system or host information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:107:system-reconnaissance","reason":"This is a safety note to check whether a target file exists before writing. It is not system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"64ca8af0f54a325752f08bd54e52151061ea659a","subject_content_hash":"bc67ae88a3019aedfb577eb1fd34295f884166e82ca40633901c56859d610af7","subject_tree_hash":"0579a70cc1a607c0a80213560ccc4b393af1e9053bc9da8fe57bad26f3cbd41e","subject_plugin_path":"skills/yamadashy/agent-memory","audit_payload_hash":"6d332e338365b71d75342d540d15b2af","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"64ca8af0f54a325752f08bd54e52151061ea659a","contentHash":"bc67ae88a3019aedfb577eb1fd34295f884166e82ca40633901c56859d610af7","treeHash":"0579a70cc1a607c0a80213560ccc4b393af1e9053bc9da8fe57bad26f3cbd41e","pluginPath":"skills/yamadashy/agent-memory","auditPayloadHash":"6d332e338365b71d75342d540d15b2af"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"unavailable","url":null,"status":null},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"unavailable","verificationState":"not_verified"},"isLatest":true}}