{"data":{"skill":{"slug":"zenlee123-routerbase-api-integration","name":"routerbase-api-integration","icon":"📦","repo":"https://github.com/zenlee123/routerbase-agent-skills/tree/main/skills/routerbase-api-integration","status":"approved","author":"zenlee123","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"cf401091-0072-4462-af8d-6f018e490cef","skill_id":"dd8d9ad7-0090-4f7f-8f77-09ff3fb43d9a","version":2,"content_hash":"v3:6dab19906b1e4121c46ce2353d0b5a559b20657c:3015367cafc6437d3170f777a12ee4fba1600fe7906f6f9dce18c3b840b47ffc:759fdbfaa94c799b2a3482f08363ef4e829cd313a611415ebc25ee2450bc6340:736b696c6c732f7a656e6c65653132332f726f75746572626173652d6170692d696e746567726174696f6e:72593eb7148dd9da86f3cf5dc2e1f21e","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Review found no executable scripts, hidden prompt injection, or secret exfiltration intent. Static alerts are documentation artifacts: RouterBase endpoint URLs, environment variable placeholders, and markdown code fences. Live RouterBase requests remain external network activity and should require user intent and credentials.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"references/routerbase-api.md","line_end":32,"line_start":32},{"file":"references/routerbase-api.md","line_end":33,"line_start":33},{"file":"references/routerbase-api.md","line_end":34,"line_start":34},{"file":"references/routerbase-api.md","line_end":35,"line_start":35},{"file":"references/routerbase-api.md","line_end":36,"line_start":36},{"file":"references/routerbase-api.md","line_end":37,"line_start":37},{"file":"references/routerbase-api.md","line_end":38,"line_start":38},{"file":"references/routerbase-api.md","line_end":39,"line_start":39},{"file":"references/routerbase-api.md","line_end":40,"line_start":40},{"file":"references/routerbase-api.md","line_end":71,"line_start":71},{"file":"references/routerbase-api.md","line_end":87,"line_start":87},{"file":"references/routerbase-api.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":65,"line_start":65}]},{"factor":"env_access","evidence":[{"file":"references/routerbase-api.md","line_end":86,"line_start":86},{"file":"references/routerbase-api.md","line_end":86,"line_start":86},{"file":"references/routerbase-api.md","line_end":70,"line_start":70},{"file":"references/routerbase-api.md","line_end":23,"line_start":23},{"file":"references/routerbase-api.md","line_end":27,"line_start":27},{"file":"references/routerbase-api.md","line_end":70,"line_start":70},{"file":"references/routerbase-api.md","line_end":86,"line_start":86},{"file":"references/routerbase-api.md","line_end":125,"line_start":125},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":87,"line_start":87}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":12,"line_start":12},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":42,"line_start":27},{"file":"SKILL.md","line_end":46,"line_start":42},{"file":"SKILL.md","line_end":60,"line_start":46},{"file":"SKILL.md","line_end":64,"line_start":60},{"file":"SKILL.md","line_end":72,"line_start":64},{"file":"SKILL.md","line_end":76,"line_start":72},{"file":"SKILL.md","line_end":79,"line_start":76},{"file":"SKILL.md","line_end":80,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":3,"total_lines":227,"audit_model":"codex","audited_at":"2026-07-06T17:07:49.048+00:00","created_at":"2026-07-16T11:00:57.259811+00:00","static_findings":[{"id":"network:references/routerbase-api.md:32:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"POST https://routerbase.com/v1/chat/completions","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:references/routerbase-api.md:33:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"POST https://routerbase.com/v1/images/generations","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:references/routerbase-api.md:34:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"POST https://routerbase.com/v1/videos/generations","category":"network","line_end":34,"severity":"low","line_start":34},{"id":"network:references/routerbase-api.md:35:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"POST https://routerbase.com/v1/audio/speech","category":"network","line_end":35,"severity":"low","line_start":35},{"id":"network:references/routerbase-api.md:36:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"POST https://routerbase.com/v1/audio/generations","category":"network","line_end":36,"severity":"low","line_start":36},{"id":"network:references/routerbase-api.md:37:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"GET  https://routerbase.com/api/v1/models","category":"network","line_end":37,"severity":"low","line_start":37},{"id":"network:references/routerbase-api.md:38:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"GET  https://routerbase.com/api/v1/models/{model_id}","category":"network","line_end":38,"severity":"low","line_start":38},{"id":"network:references/routerbase-api.md:39:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"GET  https://routerbase.com/api/v1/models/{model_id}/pricing","category":"network","line_end":39,"severity":"low","line_start":39},{"id":"network:references/routerbase-api.md:40:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"GET  https://routerbase.com/api/v1/pricing","category":"network","line_end":40,"severity":"low","line_start":40},{"id":"network:references/routerbase-api.md:71:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"base_url=\"https://routerbase.com/v1\",","category":"network","line_end":71,"severity":"low","line_start":71},{"id":"network:references/routerbase-api.md:87:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"baseURL: \"https://routerbase.com/v1\",","category":"network","line_end":87,"severity":"low","line_start":87},{"id":"network:references/routerbase-api.md:114:hardcoded-url","file":"references/routerbase-api.md","pattern":"Hardcoded URL","snippet":"{ \"type\": \"image_url\", \"image_url\": { \"url\": \"https://example.com/image.png\" } }","category":"network","line_end":114,"severity":"low","line_start":114},{"id":"env_access:references/routerbase-api.md:86:environment-variable-access-dot-notation","file":"references/routerbase-api.md","pattern":"Environment variable access (dot notation)","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"env_access","line_end":86,"severity":"low","line_start":86},{"id":"env_access:references/routerbase-api.md:86:environment-variable-object","file":"references/routerbase-api.md","pattern":"Environment variable object","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"env_access","line_end":86,"severity":"low","line_start":86},{"id":"env_access:references/routerbase-api.md:70:python-environment-access","file":"references/routerbase-api.md","pattern":"Python environment access","snippet":"api_key=os.environ[\"ROUTERBASE_API_KEY\"],","category":"env_access","line_end":70,"severity":"low","line_start":70},{"id":"env_access:references/routerbase-api.md:23:generic-api-secret-keys","file":"references/routerbase-api.md","pattern":"Generic API/secret keys","snippet":"Authorization: Bearer <YOUR_API_KEY>","category":"env_access","line_end":23,"severity":"high","line_start":23},{"id":"env_access:references/routerbase-api.md:27:generic-api-secret-keys","file":"references/routerbase-api.md","pattern":"Generic API/secret keys","snippet":"Use `ROUTERBASE_API_KEY` in examples. Never place keys in frontend code.","category":"env_access","line_end":27,"severity":"high","line_start":27},{"id":"env_access:references/routerbase-api.md:70:generic-api-secret-keys","file":"references/routerbase-api.md","pattern":"Generic API/secret keys","snippet":"api_key=os.environ[\"ROUTERBASE_API_KEY\"],","category":"env_access","line_end":70,"severity":"high","line_start":70},{"id":"env_access:references/routerbase-api.md:86:generic-api-secret-keys","file":"references/routerbase-api.md","pattern":"Generic API/secret keys","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"env_access","line_end":86,"severity":"high","line_start":86},{"id":"env_access:references/routerbase-api.md:125:generic-api-secret-keys","file":"references/routerbase-api.md","pattern":"Generic API/secret keys","snippet":"1. Confirm `ROUTERBASE_API_KEY` is set server-side.","category":"env_access","line_end":125,"severity":"high","line_start":125},{"id":"sensitive:references/routerbase-api.md:86:environment-file-access","file":"references/routerbase-api.md","pattern":"Environment file access","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"sensitive","line_end":86,"severity":"high","line_start":86},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Read `references/routerbase-api.md` when exact endpoint details, headers, or examples are needed.","category":"external_commands","line_end":12,"severity":"medium","line_start":12},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Keep credentials out of client/browser code. Prefer `ROUTERBASE_API_KEY` in server-side environme","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Reuse the user's existing OpenAI-compatible client when possible. Change the base URL to `https:/","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":42,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":46,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```js","category":"external_commands","line_end":60,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":64,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":72,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":76,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Never paste or log real API keys. Use placeholders like `sk-rb-...` only in docs.","category":"external_commands","line_end":79,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For streaming, set `stream: true` and process Server-Sent Events or SDK stream chunks.","category":"external_commands","line_end":80,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For tool calling and JSON mode, keep the standard OpenAI fields `tools` and `response_format`.","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- For multimodal chat, use OpenAI content parts with `text` and `image_url`.","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"network:SKILL.md:3:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"description: Integrate applications with RouterBase, the OpenAI-compatible model gateway at https://","category":"network","line_end":3,"severity":"low","line_start":3},{"id":"network:SKILL.md:10:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Use [routerbase](https://routerbase.com) as an OpenAI-compatible gateway for GPT, Claude, Gemini, an","category":"network","line_end":10,"severity":"low","line_start":10},{"id":"network:SKILL.md:18:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"3. Reuse the user's existing OpenAI-compatible client when possible. Change the base URL to `https:/","category":"network","line_end":18,"severity":"low","line_start":18},{"id":"network:SKILL.md:33:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"base_url=\"https://routerbase.com/v1\",","category":"network","line_end":33,"severity":"low","line_start":33},{"id":"network:SKILL.md:51:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"baseURL: \"https://routerbase.com/v1\",","category":"network","line_end":51,"severity":"low","line_start":51},{"id":"network:SKILL.md:65:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"curl -X POST https://routerbase.com/v1/chat/completions \\","category":"network","line_end":65,"severity":"low","line_start":65},{"id":"env_access:SKILL.md:50:environment-variable-access-dot-notation","file":"SKILL.md","pattern":"Environment variable access (dot notation)","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"env_access","line_end":50,"severity":"low","line_start":50},{"id":"env_access:SKILL.md:50:environment-variable-object","file":"SKILL.md","pattern":"Environment variable object","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"env_access","line_end":50,"severity":"low","line_start":50},{"id":"env_access:SKILL.md:32:python-environment-access","file":"SKILL.md","pattern":"Python environment access","snippet":"api_key=os.environ[\"ROUTERBASE_API_KEY\"],","category":"env_access","line_end":32,"severity":"low","line_start":32},{"id":"env_access:SKILL.md:17:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"2. Keep credentials out of client/browser code. Prefer `ROUTERBASE_API_KEY` in server-side environme","category":"env_access","line_end":17,"severity":"high","line_start":17},{"id":"env_access:SKILL.md:32:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"api_key=os.environ[\"ROUTERBASE_API_KEY\"],","category":"env_access","line_end":32,"severity":"high","line_start":32},{"id":"env_access:SKILL.md:50:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"env_access","line_end":50,"severity":"high","line_start":50},{"id":"env_access:SKILL.md:66:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"-H \"Authorization: Bearer $ROUTERBASE_API_KEY\" \\","category":"env_access","line_end":66,"severity":"high","line_start":66},{"id":"env_access:SKILL.md:87:generic-api-secret-keys","file":"SKILL.md","pattern":"Generic API/secret keys","snippet":"- Include where `ROUTERBASE_API_KEY` should be configured.","category":"env_access","line_end":87,"severity":"high","line_start":87},{"id":"sensitive:SKILL.md:50:environment-file-access","file":"SKILL.md","pattern":"Environment file access","snippet":"apiKey: process.env.ROUTERBASE_API_KEY,","category":"sensitive","line_end":50,"severity":"high","line_start":50}],"finding_verdicts":[{"id":"network:references/routerbase-api.md:32:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:33:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:34:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:35:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:36:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:37:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:38:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:39:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:40:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:71:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:87:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:references/routerbase-api.md:114:hardcoded-url","reason":"This is a placeholder image URL inside a multimodal request example. It is not a covert endpoint or automatic network call.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/routerbase-api.md:86:environment-variable-access-dot-notation","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:references/routerbase-api.md:86:environment-variable-object","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:references/routerbase-api.md:70:python-environment-access","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:references/routerbase-api.md:23:generic-api-secret-keys","reason":"The line uses a placeholder token format for documentation. It does not contain a real secret or instruct disclosure of credentials.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/routerbase-api.md:27:generic-api-secret-keys","reason":"The line is a security guardrail telling users to keep keys server-side. It reduces credential exposure risk rather than creating one.","verdict":"false_positive","confidence":0.97},{"id":"env_access:references/routerbase-api.md:70:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:references/routerbase-api.md:86:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:references/routerbase-api.md:125:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:references/routerbase-api.md:86:environment-file-access","reason":"The process.env reference is a documented server-side API key example, not file-system access to a .env file. No stored secret is exposed in the skill.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:12:ruby-shell-backtick-execution","reason":"The backticks mark a local reference file name in prose. This is not shell execution or a command injection vector.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"The backticks mark inline documentation terms such as environment variables, URLs, or API fields. They are not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The backticks mark inline documentation terms such as environment variables, URLs, or API fields. They are not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The static pattern matched markdown code fences, not Ruby backtick execution. These delimit examples and do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The static pattern matched markdown code fences, not Ruby backtick execution. These delimit examples and do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The static pattern matched markdown code fences, not Ruby backtick execution. These delimit examples and do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The static pattern matched markdown code fences, not Ruby backtick execution. These delimit examples and do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The static pattern matched markdown code fences, not Ruby backtick execution. These delimit examples and do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The static pattern matched markdown code fences, not Ruby backtick execution. These delimit examples and do not execute commands.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The backticks mark inline documentation terms such as environment variables, URLs, or API fields. They are not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The backticks mark inline documentation terms such as environment variables, URLs, or API fields. They are not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The backticks mark inline documentation terms such as environment variables, URLs, or API fields. They are not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The backticks mark inline documentation terms such as environment variables, URLs, or API fields. They are not executable shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:3:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:10:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:18:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:33:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:51:hardcoded-url","reason":"The URL documents RouterBase endpoints for an API integration skill. It is an expected target service, not hidden exfiltration or automatic network behavior.","verdict":"false_positive","confidence":0.95},{"id":"network:SKILL.md:65:hardcoded-url","reason":"The RouterBase URL appears in an explicit curl example for the documented integration. The workflow says live calls should only run with credentials and user intent.","verdict":"false_positive","confidence":0.93},{"id":"env_access:SKILL.md:50:environment-variable-access-dot-notation","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:50:environment-variable-object","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:32:python-environment-access","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:17:generic-api-secret-keys","reason":"The line is a security guardrail telling users to keep keys server-side. It reduces credential exposure risk rather than creating one.","verdict":"false_positive","confidence":0.97},{"id":"env_access:SKILL.md:32:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:50:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:66:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"env_access:SKILL.md:87:generic-api-secret-keys","reason":"The line references a named environment variable for server-side configuration. It does not expose a secret value or enumerate arbitrary environment data.","verdict":"false_positive","confidence":0.95},{"id":"sensitive:SKILL.md:50:environment-file-access","reason":"The process.env reference is a documented server-side API key example, not file-system access to a .env file. No stored secret is exposed in the skill.","verdict":"false_positive","confidence":0.94}],"semantic_findings":[],"subject_marketplace_commit_sha":"6dab19906b1e4121c46ce2353d0b5a559b20657c","subject_content_hash":"3015367cafc6437d3170f777a12ee4fba1600fe7906f6f9dce18c3b840b47ffc","subject_tree_hash":"759fdbfaa94c799b2a3482f08363ef4e829cd313a611415ebc25ee2450bc6340","subject_plugin_path":"skills/zenlee123/routerbase-api-integration","audit_payload_hash":"72593eb7148dd9da86f3cf5dc2e1f21e","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"6dab19906b1e4121c46ce2353d0b5a559b20657c","contentHash":"3015367cafc6437d3170f777a12ee4fba1600fe7906f6f9dce18c3b840b47ffc","treeHash":"759fdbfaa94c799b2a3482f08363ef4e829cd313a611415ebc25ee2450bc6340","pluginPath":"skills/zenlee123/routerbase-api-integration","auditPayloadHash":"72593eb7148dd9da86f3cf5dc2e1f21e"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}