{"data":{"skill":{"slug":"zl2023github-test-engineer","name":"test-engineer","icon":"📦","repo":"https://github.com/zl2023github/software-engineer-skills/tree/main/software-engineering/test-engineer","status":"approved","author":"zl2023github","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"e2d344e9-8753-4243-bf4f-e0e7d375c041","skill_id":"b2bfda74-b404-4a3d-a0af-4de9dff0fc07","version":4,"content_hash":"v3:88a8e9a07f4c54ab105c1c41b6267c287146b07b:26b6c482c2c2e3f9e1f493fd0b47a78eef55125f9a04e7337430fcfe0da07655:656a088bccc6268601e5c5010f425dfbba3be27de1cc417cbaec719365c3b651:736b696c6c732f7a6c323032336769746875622f746573742d656e67696e656572:8d6616bb7b77fd290c7642854c2fde4a","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 19 static findings are false positives caused by Markdown formatting and multilingual prose. The skill still directs active API and load testing without authorization or production safeguards. Add explicit consent, scope, rate, and environment checks before publication.","remediation":[{"issue":"Active API and performance tests lack authorization guardrails.","severity":"high","suggestion":"Require confirmation of target ownership, environment, rate limits, duration, and rollback plans. Block production load tests by default."},{"issue":"Dependency installation and environment changes may occur without explicit approval.","severity":"medium","suggestion":"Request approval before installing packages, starting containers, changing CI files, or executing generated scripts."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":90,"line_start":90},{"file":"SKILL.md","line_end":135,"line_start":127},{"file":"SKILL.md","line_end":138,"line_start":135},{"file":"SKILL.md","line_end":145,"line_start":138},{"file":"SKILL.md","line_end":148,"line_start":145},{"file":"SKILL.md","line_end":155,"line_start":148},{"file":"SKILL.md","line_end":158,"line_start":155},{"file":"SKILL.md","line_end":164,"line_start":158},{"file":"SKILL.md","line_end":172,"line_start":164},{"file":"SKILL.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":174,"line_start":173},{"file":"SKILL.md","line_end":174,"line_start":174},{"file":"SKILL.md","line_end":179,"line_start":175},{"file":"SKILL.md","line_end":185,"line_start":179},{"file":"SKILL.md","line_end":192,"line_start":185},{"file":"SKILL.md","line_end":196,"line_start":192}]}],"critical_findings":[],"high_findings":[{"title":"Active Testing Lacks Authorization Guardrails","locations":[{"file":"SKILL.md","line_end":90,"line_start":65}],"confidence":0.96,"description":"The skill directs real API calls and performance load tests without requiring target ownership, production approval, scope, or traffic limits.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The workflow explicitly requires actual API and load-test execution. No authorization, environment, or rate-limit check appears in that workflow."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":216,"audit_model":"codex","audited_at":"2026-07-24T00:12:51.621+00:00","created_at":"2026-07-26T17:18:03.581684+00:00","static_findings":[{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**工具链**:`curl` / `httpie` / Python `requests` / `pytest`","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**工具链**:`k6` / `wrk` / `hey` / `ab`(Apache Bench)","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**深度性能测试**:对于需要完整性能测试工作流(需求分析→场景设计→脚本开发→监控采集→瓶颈分析→调优建议→报告输出)的任务,加载 `perf-fullstack-engineer` 技能配合使用,","category":"external_commands","line_end":90,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":135,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":138,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":145,"severity":"medium","line_start":138},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":148,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":155,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":158,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":164,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":172,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Web UI自动化 | Playwright | `pip install playwright && playwright install` → 生成脚本 → `pytest` 运行 |","category":"external_commands","line_end":172,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| API测试 | Python requests / curl | 生成脚本 → `python test_api.py` 执行 |","category":"external_commands","line_end":174,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 性能测试 | k6 / wrk / hey | `k6 run script.js` 或 `wrk -t4 -c100 -d30s URL` |","category":"external_commands","line_end":174,"severity":"medium","line_start":174},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 单元测试 | pytest / JUnit / Jest | `pytest -v --tb=short --junitxml=report.xml` |","category":"external_commands","line_end":179,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 容器化 | Docker Compose | `docker compose up -d` 启动测试环境 |","category":"external_commands","line_end":185,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":192,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"│   (`ops-engineer`:容器、K8s、CI/CD、监控)","category":"external_commands","line_end":196,"severity":"medium","line_start":192},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-7-06-bits-possible-b","file":"SKILL.md","pattern":"[HEURISTIC] High file entropy (7.06 bits) - possible binary/encrypted content","snippet":"File: SKILL.md","category":"obfuscation","line_end":1,"severity":"high","line_start":1}],"finding_verdicts":[{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"Line 75 uses Markdown backticks to format tool names. It contains no Ruby expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"Line 88 presents performance tool names as inline Markdown code. The backticks are documentation syntax, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"Line 90 formats another skill name with Markdown backticks. It does not evaluate or execute the enclosed text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"Lines 127 through 135 are a fenced Markdown usage example. The fence is not Ruby backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"Lines 135 through 138 contain adjacent Markdown fence boundaries and a heading. They do not define executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:138:ruby-shell-backtick-execution","reason":"Lines 138 through 145 are a fenced natural-language API testing example. No command substitution or executable Ruby is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"Lines 145 through 148 contain a Markdown fence boundary and example heading. The backticks only structure documentation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"Lines 148 through 155 are a fenced performance testing example written as prose. They are not executed by the skill file.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"Lines 155 through 158 contain a Markdown fence boundary and example heading. No shell execution mechanism exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"Lines 158 through 164 are a fenced CI workflow example. The fence is presentation syntax rather than an execution primitive.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"Lines 164 through 172 close an example and introduce a Markdown table. Backticks only format documented command names.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"Line 172 documents package installation and pytest commands inside inline Markdown code. The file does not execute those commands itself.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"Lines 173 through 174 show example test commands in a documentation table. They are not Ruby backticks or runtime command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:174:ruby-shell-backtick-execution","reason":"Line 174 documents sample k6 and wrk invocations as inline code. No executable script invokes them from this file.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"Lines 175 through 179 list example test and container commands in Markdown. The backticks only mark inline code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"Lines 179 through 185 document a Docker command and then open a fenced diagram. Neither form executes a shell command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"Lines 185 through 192 form a fenced text diagram. The triple backticks are standard Markdown delimiters.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:192:ruby-shell-backtick-execution","reason":"Lines 192 through 196 contain a formatted skill name inside a fenced diagram. There is no command execution expression.","verdict":"false_positive","confidence":0.99},{"id":"obfuscation:SKILL.md:1:heuristic-high-file-entropy-7-06-bits-possible-b","reason":"SKILL.md is readable UTF-8 Chinese Markdown with tables and examples. It contains no binary payload, encrypted block, or concealed instruction.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Active Testing Lacks Authorization Guardrails","severity":"high","locations":[{"file":"SKILL.md","line_end":90,"line_start":65}],"confidence":0.96,"description":"The skill directs real API calls and performance load tests without requiring target ownership, production approval, scope, or traffic limits.","confidence_reasoning":"The workflow explicitly requires actual API and load-test execution. No authorization, environment, or rate-limit check appears in that workflow."}],"subject_marketplace_commit_sha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","subject_content_hash":"26b6c482c2c2e3f9e1f493fd0b47a78eef55125f9a04e7337430fcfe0da07655","subject_tree_hash":"656a088bccc6268601e5c5010f425dfbba3be27de1cc417cbaec719365c3b651","subject_plugin_path":"skills/zl2023github/test-engineer","audit_payload_hash":"8d6616bb7b77fd290c7642854c2fde4a","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"88a8e9a07f4c54ab105c1c41b6267c287146b07b","contentHash":"26b6c482c2c2e3f9e1f493fd0b47a78eef55125f9a04e7337430fcfe0da07655","treeHash":"656a088bccc6268601e5c5010f425dfbba3be27de1cc417cbaec719365c3b651","pluginPath":"skills/zl2023github/test-engineer","auditPayloadHash":"8d6616bb7b77fd290c7642854c2fde4a"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/zl2023github-test-engineer/audits/4/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}