{"data":{"skill":{"slug":"zhanlincui-dispatching-parallel-agents","name":"dispatching-parallel-agents","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/dispatching-parallel-agents","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"08f508c2-d391-4cc8-ac62-f15f86190003","skill_id":"07176d0b-61a5-4944-b6ee-7af4ba241e33","version":4,"content_hash":"v2:64ca8af0f54a325752f08bd54e52151061ea659a:ffec59886a6e4debf713a6f3b9c7b66aa59c23150dca003f1ff6dafe0d7e1b2b:fb839dbb0961dc5a52c493beb8545ee314ac83100686d3b3b07734a491c26886:f9690889c4585800a797b1d2fe2c0501","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All static detections were false positives caused by Markdown code fences and ordinary checklist language. The skill is documentation for coordinating independent AI agents and contains no executable scripts, network calls, data exfiltration intent, or prompt injection content.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":32,"line_start":16},{"file":"SKILL.md","line_end":66,"line_start":32},{"file":"SKILL.md","line_end":72,"line_start":66},{"file":"SKILL.md","line_end":89,"line_start":72},{"file":"SKILL.md","line_end":108,"line_start":89},{"file":"SKILL.md","line_end":143,"line_start":108},{"file":"SKILL.md","line_end":147,"line_start":143}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":181,"audit_model":"codex","audited_at":"2026-07-08T12:39:19.399+00:00","created_at":"2026-07-08T14:54:45.848612+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dot","category":"external_commands","line_end":32,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":66,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```typescript","category":"external_commands","line_end":72,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":89,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":108,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":143,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":147,"severity":"medium","line_start":143},{"id":"blocker:SKILL.md:169:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"2. **Check for conflicts** - Did agents edit same code?","category":"blocker","line_end":169,"severity":"low","line_start":169},{"id":"blocker:SKILL.md:60:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- **Clear goal:** Make these tests pass","category":"blocker","line_end":61,"severity":"low","line_start":60}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The flagged line is a Markdown code fence for a DOT diagram, not executable Ruby or shell code. It is static documentation and does not instruct command execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The flagged line closes the DOT diagram code block. No command, interpreter instruction, or shell execution appears in this location.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"This is a fenced TypeScript example showing pseudo-code for dispatching AI tasks. It does not execute locally and does not invoke shell commands.","verdict":"false_positive","confidence":0.93},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The flagged line is only the closing fence for the TypeScript example. It contains no executable instruction or command invocation.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"This opens a Markdown example prompt used for agent task structure. The content is prose guidance and does not run a shell or Ruby command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The flagged line closes the Markdown prompt example. There is no code execution behavior or user-controlled command construction.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"This code block contains a plain text dispatch example naming three agents. It is documentation, not executable shell syntax.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:169:system-reconnaissance","reason":"The phrase 'Check for conflicts' is verification guidance for reviewing concurrent agent edits, not system reconnaissance. It narrows risk by requiring conflict review.","verdict":"false_positive","confidence":0.95},{"id":"blocker:SKILL.md:60:network-reconnaissance","reason":"The phrase 'Make these tests pass' is task goal prose, not network reconnaissance. No network probing or external host enumeration appears here.","verdict":"false_positive","confidence":0.95}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}