{"data":{"skill":{"slug":"zhanlincui-doc-coauthoring","name":"doc-coauthoring","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/doc-coauthoring","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"06ff7475-3946-4274-b93a-7ba439720712","skill_id":"88607a17-b1e4-42f7-8066-6a00f91e62be","version":2,"content_hash":"3fa55c0c16a439288e00c0864005d074","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported shell execution, weak cryptography, and network patterns, but the shell and crypto alerts are false positives from Markdown workflow text and tool names. The remaining real concerns are legitimate workflow behaviors: optional connector access to shared documents or channels, and creating or editing documentation files.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":135,"line_start":135},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":188,"line_start":188},{"file":"SKILL.md","line_end":208,"line_start":208},{"file":"SKILL.md","line_end":368,"line_start":367}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":50,"line_start":46},{"file":"SKILL.md","line_end":80,"line_start":70},{"file":"SKILL.md","line_end":304,"line_start":303}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Optional Connector Access to Shared Documents and Channels","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":50,"line_start":46},{"file":"SKILL.md","line_end":80,"line_start":70},{"file":"SKILL.md","line_end":304,"line_start":303}],"confidence":0.78,"description":"The skill instructs the assistant to use available integrations to fetch shared documents or read messaging context. This is a legitimate documentation workflow, but it can expose sensitive organizational content if users grant broad connector access without reviewing scope.","confidence_reasoning":"The file explicitly tells the assistant to read shared documents or use integrations when available. The behavior is user-directed and not malicious, but it creates a real privacy and access-control concern."},{"title":"User Workspace File Creation and Editing","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":135,"line_start":135},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":188,"line_start":188},{"file":"SKILL.md","line_end":208,"line_start":208},{"file":"SKILL.md","line_end":368,"line_start":367}],"confidence":0.82,"description":"The skill directs the assistant to create Markdown files and use artifact editing tools while drafting documents. This is expected for co-authoring, but it requires normal workspace write permissions and user review before important files are overwritten or changed.","confidence_reasoning":"The instructions explicitly call for creating files and replacing document text. The purpose is legitimate, but the file-write behavior is concrete and should be disclosed."}],"low_findings":[{"title":"Static Shell Execution Alerts Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":135,"line_start":135},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":188,"line_start":188},{"file":"SKILL.md","line_end":208,"line_start":208},{"file":"SKILL.md","line_end":368,"line_start":367}],"confidence":0.95,"description":"The reported Ruby or shell backtick detections occur inside Markdown inline code references such as create_file and str_replace, plus prose about creating Markdown files. No shell command, Ruby execution, or command interpolation is present.","confidence_reasoning":"The flagged text is Markdown documentation naming editor tools or files, not executable Ruby or shell code. There is no evidence of command execution syntax beyond inline-code formatting."},{"title":"Static Weak Cryptography Alerts Are False Positives","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":8,"line_start":8},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":207,"line_start":207}],"confidence":0.96,"description":"The flagged lines contain ordinary documentation words such as doc, docs, Claude, and workflow text. No hashing, encryption, cipher selection, or cryptographic API usage is present.","confidence_reasoning":"Manual review found no cryptographic operation at the listed locations. The alerts appear to be keyword matches inside natural-language documentation."},{"title":"Static Network Reconnaissance Alert Is a False Positive","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":68,"line_start":66}],"confidence":0.94,"description":"The flagged line is an instruction for the user to provide an information dump or link shared documents. It does not describe scanning hosts, discovering services, or probing networks.","confidence_reasoning":"The line is plain workflow guidance for collecting user-provided context. No network reconnaissance command or probing behavior appears in the surrounding text."},{"title":"Hardcoded Claude URL Is Benign","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":303,"line_start":303}],"confidence":0.91,"description":"The hardcoded URL points users to Claude.ai for manual reader testing. It is not used for automatic data transfer, credential collection, or hidden outbound requests.","confidence_reasoning":"The URL is shown as a user-facing instruction to open a fresh Claude conversation. There is no code path that sends data to the URL automatically."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":376,"audit_model":"codex","audited_at":"2026-07-01T03:28:38.497+00:00","created_at":"2026-07-01T04:01:03.282654+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":2,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":4,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}