{"data":{"skill":{"slug":"zhanlincui-webapp-testing","name":"webapp-testing","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/webapp-testing","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"4565ab63-0cda-4280-b578-21618d9ebf19","skill_id":"3760fc52-a467-48d9-ac1d-1f7dda0de51f","version":1,"content_hash":"565504728310eca4b8e2f15754a82704","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged 38 patterns, but manual review confirms all HIGH-severity findings are false positives. The 'weak cryptographic algorithm' detections are scanner errors on argparse code. Shell backtick findings are Markdown documentation formatting. Subprocess usage in with_server.py is intentional server management functionality requiring explicit CLI invocation. Hardcoded localhost URLs and temp file writes are expected for local testing toolkit.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"scripts/with_server.py","line_end":74,"line_start":69},{"file":"scripts/with_server.py","line_end":89,"line_start":88}]},{"factor":"filesystem","evidence":[{"file":"examples/console_logging.py","line_end":32,"line_start":31},{"file":"examples/element_discovery.py","line_end":38,"line_start":37}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Subprocess with shell=True","locations":[{"file":"scripts/with_server.py","line_end":74,"line_start":69}],"confidence":0.95,"description":"with_server.py uses subprocess.Popen with shell=True to start development servers. This is intentional functionality for a server management helper script. Commands are passed via CLI arguments, requiring explicit user invocation. Risk is mitigated by design - users explicitly provide the server commands.","confidence_reasoning":"Direct evidence of shell=True with user-provided commands, but this is the intended purpose of a server wrapper utility requiring explicit CLI invocation."}],"dangerous_patterns":[],"files_scanned":5,"total_lines":310,"audit_model":"claude","audited_at":"2026-02-24T09:29:27.653+00:00","created_at":"2026-02-24T15:49:04.142558+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}