Versioned security assessment

Report ID: SA-F7498B3E

7/1/2026, 12:12:08 AM

projection-patterns security assessment v5

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
projection-patterns
Version
v5
Maintainer
wshobson
Coverage
1 Files scanned · 489 Lines analyzed
Policy version
Unavailable

Confirmed finding summary

No confirmed security findings

The completed audit recorded no confirmed security findings. This is not proof that the Skill has no side effects.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Static analysis flagged command execution, weak cryptography, reconnaissance, and network indicators, but review found these are documentation false positives. The skill contains Markdown diagrams, Python examples, SQL templates, and two resource links, with no executable installer scripts or prompt injection attempts found.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

1 Files scanned · 489 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 2 evidence locations

Filesystem access

May read or write local files.

Not recorded by this audit

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 11 evidence locations

Capability review items (1)
Low
Documentation links to external resources
Verdict: FALSE_POSITIVE for runtime network risk. The hardcoded URLs are resource links in a Markdown references section. They are not fetched by code and do not transmit data.
The URLs are visible documentation references only. No script, request call, or automatic network behavior is present in the skill file.

Risk findings

Confirmed security concerns are separated from items that still need review.

No confirmed security findings were recorded for this completed audit.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (3)
Low
False positive: Markdown code fences flagged as shell execution
Verdict: FALSE_POSITIVE. The backtick findings are Markdown code block fences around diagrams and Python examples, not Ruby or shell execution. They do not execute commands when the skill is loaded.
The exact lines are Markdown fences that delimit diagrams or sample Python code. No shell command, Ruby backtick expression, or execution context is present.
Low
False positive: weak cryptography substring matches
Verdict: FALSE_POSITIVE. The weak cryptography alerts match ordinary words such as description, Description, and Design. No hashing, cipher selection, or cryptographic API usage appears at these locations.
The reviewed lines contain plain prose or data field names. There is no evidence of MD5, DES, SHA-1, or any cryptographic implementation.
Low
False positive: SQL WHERE clauses flagged as reconnaissance
Verdict: FALSE_POSITIVE. The system reconnaissance alerts occur on parameterized SQL WHERE clauses inside read-model examples. They query application tables and do not inspect the host system.
Each location is an SQL predicate using placeholders such as $1. The code examples do not call operating system discovery commands or enumerate local resources.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable