Versioned security assessment

Report ID: SA-E98C3943

6/30/2026, 5:02:11 PM

helpdesk-automation security assessment v2

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
helpdesk-automation
Version
v2
Maintainer
sickn33
Coverage
1 Files scanned · 167 Lines analyzed
Policy version
Unavailable

Confirmed finding summary

No confirmed security findings

The completed audit recorded no confirmed security findings. This is not proof that the Skill has no side effects.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Static shell-execution and weak-cryptography alerts are false positives caused by markdown inline code, frontmatter, and tool names in SKILL.md. The confirmed risk is legitimate but meaningful: the skill requires a third-party Rube MCP endpoint and HelpDesk authentication, so ticket data may pass through an external integration.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

1 Files scanned · 167 Lines analyzed

2 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 2 evidence locations

Filesystem access

May read or write local files.

Not recorded by this audit

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Not recorded by this audit

Capability review items (2)
Medium
Third-Party MCP Endpoint Handles HelpDesk Access
The skill instructs users to add the Rube MCP endpoint and use it for HelpDesk operations. This is expected behavior, but it creates a third-party network dependency for support ticket data.
The hardcoded MCP endpoint is explicitly documented and tied to HelpDesk automation. This is legitimate integration behavior, but it materially affects data exposure and trust boundaries.
Medium
HelpDesk Authentication Is Delegated Through Rube MCP
The setup flow tells users to manage a HelpDesk connection and follow an authentication link when the connection is not active. This can grant ticket-system access through the external MCP provider.
The instructions clearly require HelpDesk connection management and authentication. No malicious intent is shown, but the access delegation should be reviewed before publication.

Risk findings

Confirmed security concerns are separated from items that still need review.

No confirmed security findings were recorded for this completed audit.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (3)
Low
Markdown Inline Code Misidentified as Shell Execution
The external command alerts are false positives. The referenced backticks are markdown formatting for MCP tool names, parameters, and examples, not Ruby or shell execution.
The inspected file is markdown documentation and contains no executable Ruby code or shell command invocation. The flagged backticks delimit inline code and fenced examples.
Low
Weak Cryptography Alerts Are False Positives
The weak cryptography alerts are not supported by semantic context. SKILL.md contains helpdesk workflow documentation and no cryptographic functions, algorithms, hashes, or encryption operations.
Manual review found only prose, tool names, and parameter descriptions at the reported locations. There is no evidence of MD5, SHA1, DES, RC4, or similar cryptographic use.
Low
System Reconnaissance Alert Is Benign Rate-Limit Guidance
The system reconnaissance alert is a false positive. The relevant line advises keeping page sizes reasonable to avoid HelpDesk API timeouts, not collecting host or environment details.
The line is operational guidance about API pagination and timeouts. No commands, probes, host inventory, or environment discovery instructions are present.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable