Versioned security assessment

Report ID: SA-97C6031A

6/28/2026, 1:12:23 PM

agentic-structure security assessment v6

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
agentic-structure
Version
v6
Maintainer
BackGwa
Coverage
8 Files scanned · 1,243 Lines analyzed
Policy version
Unavailable

Confirmed finding summary

No confirmed security findings

The completed audit recorded no confirmed security findings. This is not proof that the Skill has no side effects.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Static analysis reported many critical and high patterns, but review found them to be documentation false positives, mostly Markdown backticks, security terminology, and examples that warn against unsafe practices. No prompt injection, credential access, malware behavior, or command execution intent was found. The remaining low risk is that the knowledge protocol describes creating reference files and using web fetches for documentation.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

8 Files scanned · 1,243 Lines analyzed

2 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 3 evidence locations

Filesystem access

May read or write local files.

Observed in 4 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Not recorded by this audit

Capability review items (2)
Low
Filesystem Reference Workflow Requires Awareness
The skill instructs agents to create and update reference Markdown files under references/[topic]. This is a legitimate documentation workflow, not malicious persistence. Risk is low because paths are scoped and no sensitive files are targeted. Confidence: 0.82. Confidence reasoning: Direct file creation guidance appears in the knowledge protocol, but the context is documentation for user-provided references and cleanup.
Direct file creation guidance appears in the knowledge protocol, but the context is documentation for user-provided references and cleanup.
Low
Web Reference Workflow Requires Source Review
The skill tells agents to use web fetching when users provide URLs or when technical information is needed. This is a bounded research workflow, not data exfiltration. Risk is low because it does not direct sending secrets or private code to external services. Confidence: 0.80. Confidence reasoning: The network-related guidance is explicit, but its purpose is retrieving and documenting external technical references.
The network-related guidance is explicit, but its purpose is retrieving and documenting external technical references.

Risk findings

Confirmed security concerns are separated from items that still need review.

No confirmed security findings were recorded for this completed audit.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (2)
Low
Static Critical and High Matches Are Documentation False Positives
The Windows SAM and weak cryptography alerts do not indicate credential access or unsafe cryptography. The reviewed lines are guideline links, security advice, or recommendations against MD5, SHA-1, and raw SHA-256 for passwords. Confidence: 0.96. Confidence reasoning: The cited files contain prose and security best practices, with no executable code or instructions to access credential stores.
The cited files contain prose and security best practices, with no executable code or instructions to access credential stores.
Low
External Command Alerts Are Markdown and Tool-Name False Positives
The Ruby backtick execution alerts are caused by Markdown code fences, inline code, and references to Read, Grep, Glob, and WebFetch. No shell execution command or arbitrary command template was found. Confidence: 0.94. Confidence reasoning: The matched backticks wrap documentation examples and filenames, not executable Ruby or shell code.
The matched backticks wrap documentation examples and filenames, not executable Ruby or shell code.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable