Versioned security assessment

Report ID: SA-6D0B1144

10/5/2026, 5:46:31 PM

executor-initiative security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
executor-initiative
Version
v1
Maintainer
atri10
Coverage
2 Files scanned Β· 706 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

2 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

All 168 static alerts are false positives for their reported patterns: Markdown delimiters, sibling references, a registry lock, and routine workflow operations. Two semantic risks remain: documented unlocked transitions can lose updates, and the verification checklist can record intake approval before charter presentation. No evidence found of malware, exfiltration, or audit-directed prompt injection; referenced dependency scripts were unavailable for review.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

2 Files scanned Β· 706 Lines analyzed

2 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Observed in 11 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (2)

RISK-001 High
Verification Checklist Can Record Unapproved Intake
The checklist says to run checks when presenting the charter, including a state-changing intake-pass command. This can record approval before the required human decision.
The checklist directly requests a pass during presentation, while the intake gate requires prior approval. Documented artifact checks do not establish human authorization.
RISK-002 Medium
Concurrent Transitions Can Lose Lifecycle Records
The skill states that phase and status updates lack locking and can lose updates in shared indexes. Prose serialization rules do not coordinate independent agents.
The source explicitly documents unlocked writes and lost updates. The dependency implementation was unavailable, so this finding concerns the documented workflow risk.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    The verification checklist records an intake pass before the charter is presented for approval.
    Use read-only checks before presentation. Move the intake-pass command after explicit approval and record the approver and approval evidence.
  2. FIX-002
    Medium
    Phase and status transitions are documented as rewriting shared records without a mutex.
    Lock the full read-modify-write operation for both indexes. Use atomic writes and test concurrent transitions for lost updates.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
6d0b11444384184b7ae743742a7e233a9a705cd9
Content hash
3a180f0e9eb31bd71d3859cd50819f31f123e3834884f9c324f4febdc407907c
Tree hash
26aa365f34056c2faf6bb4e18b72cc874c1550adcb7e2becc364d1221d12ca96
Skill path
skills/atri10/executor-initiative
Audit payload hash
af53b4342d1f297b87fb30e7abb3bdc7

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active