{"data":{"skill":{"slug":"zl2023github-data-engineer","name":"data-engineer","icon":"📦","repo":"https://github.com/zl2023github/software-engineer-skills/tree/main/software-engineering/data-engineer","status":"approved","author":"zl2023github","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"553988c9-ef77-414f-9655-7daf3531a72d","skill_id":"4982ae02-f927-44fd-8207-bca632577c98","version":4,"content_hash":"v3:88a8e9a07f4c54ab105c1c41b6267c287146b07b:5f5fae528bffd45c6dd10642f2e91f781dcf7ada4c89ca4f22c9bcd9cfc2235b:83caa09a6e980e93d04f3e6fd5ac3555ca6cf26b9eafb3940ea57f96261f9be7:736b696c6c732f7a6c323032336769746875622f646174612d656e67696e656572:f4fe364361c293329527f22848ee170d","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 42 backtick detections are Markdown fences or inline code, not shell execution. Eight reconnaissance matches are schema identifiers, and multilingual diagrams explain the entropy alert. Destructive delete and overwrite examples still lack confirmation, backup, and environment safeguards.","remediation":[{"issue":"Destructive database and overwrite examples lack safety gates.","severity":"medium","suggestion":"Require explicit confirmation, environment checks, scoped dates, backups, and dry runs before delete or overwrite operations."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":264,"line_start":89},{"file":"SKILL.md","line_end":296,"line_start":264},{"file":"SKILL.md","line_end":300,"line_start":296},{"file":"SKILL.md","line_end":333,"line_start":300},{"file":"SKILL.md","line_end":337,"line_start":333},{"file":"SKILL.md","line_end":370,"line_start":337},{"file":"SKILL.md","line_end":374,"line_start":370},{"file":"SKILL.md","line_end":409,"line_start":374},{"file":"SKILL.md","line_end":413,"line_start":409},{"file":"SKILL.md","line_end":442,"line_start":413},{"file":"SKILL.md","line_end":446,"line_start":442},{"file":"SKILL.md","line_end":475,"line_start":446},{"file":"SKILL.md","line_end":479,"line_start":475},{"file":"SKILL.md","line_end":508,"line_start":479},{"file":"SKILL.md","line_end":512,"line_start":508},{"file":"SKILL.md","line_end":548,"line_start":512},{"file":"SKILL.md","line_end":552,"line_start":548},{"file":"SKILL.md","line_end":586,"line_start":552},{"file":"SKILL.md","line_end":633,"line_start":586},{"file":"SKILL.md","line_end":633,"line_start":633},{"file":"SKILL.md","line_end":634,"line_start":634},{"file":"SKILL.md","line_end":636,"line_start":635},{"file":"SKILL.md","line_end":636,"line_start":636},{"file":"SKILL.md","line_end":704,"line_start":659},{"file":"SKILL.md","line_end":733,"line_start":704},{"file":"SKILL.md","line_end":739,"line_start":733},{"file":"SKILL.md","line_end":743,"line_start":739},{"file":"SKILL.md","line_end":782,"line_start":743},{"file":"SKILL.md","line_end":787,"line_start":782},{"file":"SKILL.md","line_end":826,"line_start":787},{"file":"SKILL.md","line_end":829,"line_start":826},{"file":"SKILL.md","line_end":892,"line_start":829},{"file":"SKILL.md","line_end":895,"line_start":892},{"file":"SKILL.md","line_end":947,"line_start":895},{"file":"SKILL.md","line_end":950,"line_start":947},{"file":"SKILL.md","line_end":1007,"line_start":950},{"file":"SKILL.md","line_end":1013,"line_start":1007},{"file":"SKILL.md","line_end":1014,"line_start":1013},{"file":"SKILL.md","line_end":1015,"line_start":1014},{"file":"SKILL.md","line_end":1016,"line_start":1015},{"file":"SKILL.md","line_end":1017,"line_start":1016},{"file":"SKILL.md","line_end":1018,"line_start":1017}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Destructive Data Operations Lack Guardrails","locations":[{"file":"SKILL.md","line_end":698,"line_start":698},{"file":"SKILL.md","line_end":825,"line_start":819}],"confidence":0.96,"description":"The command reference shows an ALTER TABLE DELETE, and the PySpark template uses overwrite mode. Neither example requires confirmation, backup verification, or a dry run.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Both destructive operations appear directly in reusable examples, with no adjacent safety gate. The placeholder targets reduce immediate impact but not reuse risk."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":1058,"audit_model":"codex","audited_at":"2026-07-23T23:28:01.511+00:00","created_at":"2026-07-26T15:26:53.412688+00:00","static_findings":[{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":264,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":296,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":300,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":333,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":337,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":370,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:370:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":374,"severity":"medium","line_start":370},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":409,"severity":"medium","line_start":374},{"id":"external_commands:SKILL.md:409:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":413,"severity":"medium","line_start":409},{"id":"external_commands:SKILL.md:413:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":442,"severity":"medium","line_start":413},{"id":"external_commands:SKILL.md:442:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":446,"severity":"medium","line_start":442},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":475,"severity":"medium","line_start":446},{"id":"external_commands:SKILL.md:475:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":479,"severity":"medium","line_start":475},{"id":"external_commands:SKILL.md:479:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":508,"severity":"medium","line_start":479},{"id":"external_commands:SKILL.md:508:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":512,"severity":"medium","line_start":508},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":548,"severity":"medium","line_start":512},{"id":"external_commands:SKILL.md:548:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":552,"severity":"medium","line_start":548},{"id":"external_commands:SKILL.md:552:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":586,"severity":"medium","line_start":552},{"id":"external_commands:SKILL.md:586:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":633,"severity":"medium","line_start":586},{"id":"external_commands:SKILL.md:633:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 表名:`{层级}_{主题域}_{表名}`(如 `dwd_trade_order_detail`)","category":"external_commands","line_end":633,"severity":"medium","line_start":633},{"id":"external_commands:SKILL.md:634:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 字段:snake_case,主键 `id`,外键 `{表名}_id`","category":"external_commands","line_end":634,"severity":"medium","line_start":634},{"id":"external_commands:SKILL.md:635:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 分区字段:`dt`(日期分区,格式 yyyy-MM-dd)","category":"external_commands","line_end":636,"severity":"medium","line_start":635},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- 时间字段:`create_time`、`update_time`","category":"external_commands","line_end":636,"severity":"medium","line_start":636},{"id":"external_commands:SKILL.md:659:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":704,"severity":"medium","line_start":659},{"id":"external_commands:SKILL.md:704:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":733,"severity":"medium","line_start":704},{"id":"external_commands:SKILL.md:733:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":739,"severity":"medium","line_start":733},{"id":"external_commands:SKILL.md:739:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":743,"severity":"medium","line_start":739},{"id":"external_commands:SKILL.md:743:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":782,"severity":"medium","line_start":743},{"id":"external_commands:SKILL.md:782:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":787,"severity":"medium","line_start":782},{"id":"external_commands:SKILL.md:787:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":826,"severity":"medium","line_start":787},{"id":"external_commands:SKILL.md:826:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":829,"severity":"medium","line_start":826},{"id":"external_commands:SKILL.md:829:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":892,"severity":"medium","line_start":829},{"id":"external_commands:SKILL.md:892:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":895,"severity":"medium","line_start":892},{"id":"external_commands:SKILL.md:895:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":947,"severity":"medium","line_start":895},{"id":"external_commands:SKILL.md:947:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":950,"severity":"medium","line_start":947},{"id":"external_commands:SKILL.md:950:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```sql","category":"external_commands","line_end":1007,"severity":"medium","line_start":950},{"id":"external_commands:SKILL.md:1007:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":1013,"severity":"medium","line_start":1007},{"id":"external_commands:SKILL.md:1013:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `arch-c4-diagram` | 需要画数据架构图时加载 |","category":"external_commands","line_end":1014,"severity":"medium","line_start":1013},{"id":"external_commands:SKILL.md:1014:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `arch-adr` | 需要记录数据架构决策时加载 |","category":"external_commands","line_end":1015,"severity":"medium","line_start":1014},{"id":"external_commands:SKILL.md:1015:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `arch-tech-evaluation` | 需要技术选型评估时加载 |","category":"external_commands","line_end":1016,"severity":"medium","line_start":1015},{"id":"external_commands:SKILL.md:1016:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ops-engineer` | 需要部署/运维数据基础设施时加载 |","category":"external_commands","line_end":1017,"severity":"medium","line_start":1016},{"id":"external_commands:SKILL.md:1017:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `backend-developer` | 需要开发数据服务 API 时加载 |","category":"external_commands","line_end":1018,"severity":"medium","line_start":1017},{"id":"blocker:SKILL.md:746:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"order_id BIGINT,","category":"blocker","line_end":746,"severity":"low","line_start":746},{"id":"blocker:SKILL.md:747:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"user_id BIGINT,","category":"blocker","line_end":747,"severity":"low","line_start":747},{"id":"blocker:SKILL.md:748:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"product_id BIGINT,","category":"blocker","line_end":748,"severity":"low","line_start":748},{"id":"blocker:SKILL.md:898:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"event_id STRING,","category":"blocker","line_end":898,"severity":"low","line_start":898},{"id":"blocker:SKILL.md:899:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"user_id STRING,","category":"blocker","line_end":899,"severity":"low","line_start":899},{"id":"blocker:SKILL.md:958:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"id AS order_id,","category":"blocker","line_end":958,"severity":"low","line_start":958},{"id":"blocker:SKILL.md:1002:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"LEFT JOIN {{ ref('dim_product') }} p ON o.product_id = p.product_id","category":"blocker","line_end":1002,"severity":"low","line_start":1002},{"id":"blocker:SKILL.md:1054:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| 架构图 | Mermaid | 数据管道架构、数据流图 |","category":"blocker","line_end":1054,"severity":"low","line_start":1054},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-6-53-bits-possible-b","file":"SKILL.md","pattern":"[HEURISTIC] High file entropy (6.53 bits) - possible binary/encrypted content","snippet":"File: SKILL.md","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a workflow diagram. It is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence that closes a workflow diagram. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:370:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:374:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:409:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:413:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:442:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:475:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:479:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:508:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:548:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:552:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a documented scenario. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:586:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence that closes a data-lake scenario. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:633:ruby-shell-backtick-execution","reason":"The backticks only format table naming examples in Markdown. No command substitution or executable shell context exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:634:ruby-shell-backtick-execution","reason":"The backticks only format primary-key and foreign-key names in Markdown. No command execution exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:635:ruby-shell-backtick-execution","reason":"The backticks only format a partition column name in Markdown. No command execution exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","reason":"The backticks only format timestamp column names in Markdown. No command execution exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:659:ruby-shell-backtick-execution","reason":"The token is a fenced Bash reference block delimiter, not a backtick substitution expression. The documented commands receive separate semantic review.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:704:ruby-shell-backtick-execution","reason":"The matched token closes a fenced Bash reference block. It does not itself execute any command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:733:ruby-shell-backtick-execution","reason":"The matched token is a Markdown code fence around a star-schema diagram. It is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:739:ruby-shell-backtick-execution","reason":"The matched token closes a Markdown diagram fence. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:743:ruby-shell-backtick-execution","reason":"The token opens a fenced SQL example. It is Markdown syntax, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:782:ruby-shell-backtick-execution","reason":"The token closes a fenced SQL example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:787:ruby-shell-backtick-execution","reason":"The token opens a fenced Python example. It is Markdown syntax, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:826:ruby-shell-backtick-execution","reason":"The token closes a fenced Python example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:829:ruby-shell-backtick-execution","reason":"The token opens a fenced Python example. It is Markdown syntax, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:892:ruby-shell-backtick-execution","reason":"The token closes a fenced Python example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:895:ruby-shell-backtick-execution","reason":"The token opens a fenced SQL example. It is Markdown syntax, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:947:ruby-shell-backtick-execution","reason":"The token closes a fenced SQL example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:950:ruby-shell-backtick-execution","reason":"The token opens a fenced dbt SQL example. It is Markdown syntax, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:1007:ruby-shell-backtick-execution","reason":"The token closes a fenced dbt SQL example. It does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:1013:ruby-shell-backtick-execution","reason":"The backticks format a skill name in a Markdown table. They do not invoke the skill or execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:1014:ruby-shell-backtick-execution","reason":"The backticks format a skill name in a Markdown table. They do not invoke the skill or execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:1015:ruby-shell-backtick-execution","reason":"The backticks format a skill name in a Markdown table. They do not invoke the skill or execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:1016:ruby-shell-backtick-execution","reason":"The backticks format a skill name in a Markdown table. They do not invoke the skill or execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:1017:ruby-shell-backtick-execution","reason":"The backticks format a skill name in a Markdown table. They do not invoke the skill or execute a command.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:746:system-reconnaissance","reason":"The text declares an order_id column in an illustrative SQL schema. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:747:system-reconnaissance","reason":"The text declares a user_id column in an illustrative SQL schema. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:748:system-reconnaissance","reason":"The text declares a product_id column in an illustrative SQL schema. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:898:system-reconnaissance","reason":"The text declares an event_id column in an illustrative Flink table. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:899:system-reconnaissance","reason":"The text declares a user_id column in an illustrative Flink table. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:958:system-reconnaissance","reason":"The text aliases a database field in an illustrative dbt query. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:1002:system-reconnaissance","reason":"The text is a relational join in an illustrative dbt model. It does not inspect the host system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:1054:system-reconnaissance","reason":"The text names Mermaid as an architecture-diagram output format. It performs no system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-6-53-bits-possible-b","reason":"The file is readable multilingual Markdown with Unicode diagrams and many technical examples. That content explains the entropy without binary, encrypted, or hidden payloads.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Destructive Data Operations Lack Guardrails","severity":"medium","locations":[{"file":"SKILL.md","line_end":698,"line_start":698},{"file":"SKILL.md","line_end":825,"line_start":819}],"confidence":0.96,"description":"The command reference shows an ALTER TABLE DELETE, and the PySpark template uses overwrite mode. Neither example requires confirmation, backup verification, or a dry run.","confidence_reasoning":"Both destructive operations appear directly in reusable examples, with no adjacent safety gate. The placeholder targets reduce immediate impact but not reuse risk."}],"subject_marketplace_commit_sha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","subject_content_hash":"5f5fae528bffd45c6dd10642f2e91f781dcf7ada4c89ca4f22c9bcd9cfc2235b","subject_tree_hash":"83caa09a6e980e93d04f3e6fd5ac3555ca6cf26b9eafb3940ea57f96261f9be7","subject_plugin_path":"skills/zl2023github/data-engineer","audit_payload_hash":"f4fe364361c293329527f22848ee170d","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","contentHash":"5f5fae528bffd45c6dd10642f2e91f781dcf7ada4c89ca4f22c9bcd9cfc2235b","treeHash":"83caa09a6e980e93d04f3e6fd5ac3555ca6cf26b9eafb3940ea57f96261f9be7","pluginPath":"skills/zl2023github/data-engineer","auditPayloadHash":"f4fe364361c293329527f22848ee170d"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/zl2023github-data-engineer/audits/4/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}