{"data":{"skill":{"slug":"zhanlincui-finishing-a-development-branch","name":"finishing-a-development-branch","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/finishing-a-development-branch","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"538dd1e1-20a7-4466-bd7e-c8641280171a","skill_id":"d48f0fa1-bb5c-4824-ba39-ce4de14da676","version":1,"content_hash":"f39b9d433d16dd482b30157a9b263426","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"All 27 static findings are false positives. The skill contains documentation (markdown instructions) showing example git commands, not actual executable code with command injection risks. The YAML frontmatter flagged as 'weak cryptographic algorithm' is standard skill metadata. The 'external_commands' patterns are markdown code blocks showing example commands users should run, not Ruby/shell backtick execution.","remediation":[],"risk_factor_evidence":[],"critical_findings":[],"high_findings":[{"title":"Weak Cryptographic Algorithm (FALSE POSITIVE)","locations":[{"file":"SKILL.md","line_end":3,"line_start":3}],"confidence":0.95,"description":"Static scanner flagged YAML frontmatter 'name:' field as cryptographic. This is standard skill metadata, not cryptographic code.","confidence_reasoning":"YAML frontmatter contains skill name/description, not cryptographic algorithms"}],"medium_findings":[{"title":"External Commands in Documentation (FALSE POSITIVE)","locations":[{"file":"SKILL.md","line_end":25,"line_start":22},{"file":"SKILL.md","line_end":45,"line_start":44},{"file":"SKILL.md","line_end":85,"line_start":70},{"file":"SKILL.md","line_end":104,"line_start":91},{"file":"SKILL.md","line_end":132,"line_start":129},{"file":"SKILL.md","line_end":148,"line_start":141}],"confidence":0.92,"description":"23 instances flagged as 'Ruby/shell backtick execution' are markdown code blocks containing example shell commands for documentation. The skill provides instructions to Claude on what git commands to run, not actual code execution.","confidence_reasoning":"These are markdown fenced code blocks (```bash) showing example commands, not backtick execution. Standard documentation pattern for skill workflows."}],"low_findings":[{"title":"Filesystem Access in Documentation (FALSE POSITIVE)","locations":[{"file":"SKILL.md","line_end":44,"line_start":44}],"confidence":0.9,"description":"References to /dev/null are in example command strings showing stderr redirection, not actual device file access","confidence_reasoning":"/dev/null in '2>/dev/null' is a standard shell redirection example in documentation"}],"dangerous_patterns":[],"files_scanned":1,"total_lines":201,"audit_model":"claude","audited_at":"2026-02-24T09:41:39.593+00:00","created_at":"2026-02-24T15:48:59.813406+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}