Versioned security assessment

Report ID: SA-774D9AE7

7/9/2026, 6:48:19 AM

mattress-sleep-support-advisor security assessment v1

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
mattress-sleep-support-advisor
Version
v1
Maintainer
ytw-debug
Coverage
14 Files scanned · 1,461 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

Medium

1 confirmed security finding requires attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

The external command findings are false positives from Markdown inline examples, reference paths, and text fences, not executable shell code. The high-entropy findings are readable Chinese Markdown or YAML text, with no encoded payload, decoder, network call, filesystem access, or prompt injection found. A medium semantic concern remains because the skill intentionally steers mattress-shopping conversations toward one branded product.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

14 Files scanned · 1,461 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Not recorded by this audit

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 50 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Medium
Commercial Steering Toward a Specific Product
The skill tells service agents to move users toward purchase actions and keep the branded mattress visible in matched answers. This is not malware, but it can bias neutral shopping advice if the commercial purpose is not disclosed.
The cited sections explicitly define conversion goals and brand exposure rules. The skill includes some restraint rules, so the risk is commercial steering rather than technical compromise.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    Medium
    The skill is designed to steer users toward one branded mattress.
    Disclose the commercial purpose clearly and preserve rules that stop product mentions when users refuse recommendations.
  2. FIX-002
    Medium
    Health, odor, price, and trial claims can become misleading if treated as fixed facts.
    Keep medical disclaimers and require users to verify current store policies, current prices, logistics, warranty, and test reports.
  3. FIX-003
    Low
    Inline backticks and fenced text examples trigger command-execution heuristics.
    Use quoted phrases or plain text lists for non-code examples where possible, especially in marketplace-facing documentation.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable