Versioned security assessment

Report ID: SA-89EDFDC7

7/23/2026, 7:06:31 AM

type-safety-validation security assessment v10

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
type-safety-validation
Version
v1.0.0
Maintainer
AI Agent Hub
Coverage
1 Files scanned · 326 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

Medium

1 confirmed security finding requires attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

All 36 static findings are false positives caused by Markdown syntax, TypeScript examples, sample URLs, relative imports, validation chains, and ordinary identifiers. One medium semantic issue remains: the examples expose database reads and writes without authentication or authorization.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

1 Files scanned · 326 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 6 evidence locations

Filesystem access

May read or write local files.

Observed in 3 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 22 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Medium
Unauthenticated Read and Write Procedures
The examples expose user lookup and post creation through procedures with no authentication or authorization checks. Adoption as shown can permit unauthorized reads and writes.
The first example uses a direct t.procedure, and the second explicitly uses publicProcedure for a database write. Neither example includes access control.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    Medium
    API examples expose user lookup and post creation without access control.
    Use authenticated procedures, enforce role and ownership checks, and explain authorization requirements before each database read or write.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
89edfdc710d0846129dcee6a929477b04f08052c
Content hash
c09b69cab4915c7a962bd7dc2e83c923d003c76633250da24dd68c74ed35746b
Tree hash
886fbbff5f3c31b616fdc61264ffea7e3514f378184ccf8b78ba16437c621166
Skill path
skills/ariegoldkin/type-safety-validation
Audit payload hash
3f322aa294b61e4c12ea9ff87576560d

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active