Versioned security assessment

Report ID: SA-C68DF504

7/18/2026, 10:24:18 AM

context-daddy security assessment v11

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: claude Latest published report
Skill name
context-daddy
Version
v11
Maintainer
ChipFlow
Coverage
10 Files scanned · 1,450 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

Low

1 confirmed security finding requires attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

All 94 static findings are false positives caused by documentation, metadata, and static assets. The reviewed material describes local indexing and optional tooling, with no evidence of credential exfiltration, malicious persistence, prompt injection, or executable command injection.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

10 Files scanned · 1,450 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 5 evidence locations

Filesystem access

May read or write local files.

Observed in 6 evidence locations

Env variables

May read values from the process environment.

Observed in 2 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Low
Unscanned file (too_large) — manual review required
[unscanned: too_large]
Force-confirmed metadata/low static finding; AI false-positive verdict rejected.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    Low
    Local project and global Claude files are created for indexes, logs, narratives, and goals.
    Document the exact files created, retention behavior, and a user-controlled cleanup procedure before installation.
  2. FIX-002
    Low
    The bundled Mermaid asset is minified and triggered a size-based scanner blind spot.
    Record the upstream Mermaid version and integrity or provenance details so future reviews can verify the bundled dependency.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
c68df504887c54bf71d2d467a1fbebde49467868
Content hash
1a839ce2b5a4a20537d74ebb1c736bdcfd7a0fee60b826370d4aa1834719c2e5
Tree hash
b63255863cf22984b0457ebfee8e01a76f3a17526f5faa0e8108751e4fe43bd8
Skill path
skills/chipflow/context-tools
Audit payload hash
67718f4394d0df6e47e91a13cad07b5d

Analysis metadata

Audit model: claude

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active