{"data":{"skill":{"slug":"zhanlincui-algorithmic-art","name":"algorithmic-art","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/algorithmic-art","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"4153307d-fa70-4def-b488-e8216f7a3563","skill_id":"53389573-e85b-4db0-a29c-418a996a7116","version":3,"content_hash":"977847c31f71f30e2bc0d3cbeb682e02","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static analysis reported command execution, weak cryptography, reconnaissance, credential access, and an obfuscation heuristic, but these were false positives from Markdown fences, art terminology, comments, and RegExp.exec usage. The only confirmed risk is external network loading of p5.js and Google Fonts in browser templates, which is a minor supply-chain and privacy dependency. No prompt injection, credential access, malicious intent, or data exfiltration evidence was found.","remediation":[],"risk_factor_evidence":[{"factor":"network","evidence":[{"file":"SKILL.md","line_end":280,"line_start":280},{"file":"templates/viewer.html","line_end":23,"line_start":23},{"file":"templates/viewer.html","line_end":24,"line_start":24},{"file":"templates/viewer.html","line_end":25,"line_start":25},{"file":"templates/viewer.html","line_end":26,"line_start":26}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"External CDN and Font Dependencies","locations":[{"file":"SKILL.md","line_end":280,"line_start":280},{"file":"templates/viewer.html","line_end":26,"line_start":23}],"confidence":0.9,"description":"The generated HTML template loads p5.js and Google Fonts from public CDNs. This is legitimate for a browser-based art artifact, but it creates minor availability, privacy, and supply-chain exposure.","confidence_reasoning":"The URLs are direct script and font dependencies used by the template. They do not send secrets or user data, so the risk is limited to external resource loading."},{"title":"Static Analyzer False Positives","locations":[{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":159,"line_start":136},{"file":"templates/generator_template.js","line_end":133,"line_start":133},{"file":"templates/viewer.html","line_end":508,"line_start":508}],"confidence":0.97,"description":"The command execution, weak cryptography, reconnaissance, Windows SAM, and dangerous-combination findings were not confirmed. The evidence points to Markdown code fences, creative-writing terms, comments, and JavaScript RegExp.exec for hex color parsing.","confidence_reasoning":"Manual review found no shell execution, Python exec, process execution, credential file access, or cryptographic operation at the flagged locations. The suspicious tokens occur in benign instructional text or normal JavaScript parsing code."}],"dangerous_patterns":[],"files_scanned":3,"total_lines":1227,"audit_model":"codex","audited_at":"2026-07-01T03:12:10.075+00:00","created_at":"2026-07-07T02:34:26.514607+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}