The static external-command alerts are Markdown code fences or inline file references, not executable Ruby or shell commands. The hidden-directory and reconnaissance alerts are illustrative workflow text and review checklist language. No evidence of prompt injection, exfiltration, or malicious intent was found.
The static external-command alerts are Markdown code fences or inline file references, not executable Ruby or shell commands. The hidden-directory and reconnaissance alerts are illustrative workflow text and review checklist language. No evidence of prompt injection, exfiltration, or malicious intent was found.
Static analysis reported 38 potential issues, but review found no malicious code, prompt injection, network calls, or executable scripts. Most findings are false positives from Markdown fences, prompt placeholders, and git SHA labels. The skill remains medium risk because it coordinates subagents that can modify files, run tests, inspect code, and commit changes in a repository.
4
Files scanned
403
Lines analyzed
6
Review items
1
False positives ignored
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The skill directs implementer subagents to implement tasks, write tests, verify changes, and commit work. This is expected for a development workflow, but it can change files and invoke project tooling in the active repository.
The cited prompt text clearly asks subagents to perform implementation, testing, and commits. This is legitimate for the skill purpose, but it creates repository modification risk.
Static external command findings are false positives. The cited sections are Markdown fenced examples and prompt templates, not Ruby or shell backtick execution.
The suspicious characters are Markdown code fences around documentation examples. No executable script, command runner, or interpolation path is present.
Static reconnaissance findings are false positives. The cited lines ask subagents to compare requirements, inspect code, and validate claims; they do not request system or network enumeration.
The wording is a code review checklist. No commands, endpoints, host discovery, port scanning, or credential discovery instructions were found.
Line 107 is an example answer choosing a user-level hook path under ~/.config. It is not a command or automated file access, but it signals possible filesystem interaction when applied to real tasks.
The line is plainly part of a documentation example, not active code. The path is still relevant because the workflow may ask subagents to edit user-level configuration during real tasks.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Static analysis reported 38 potential issues, but review found no malicious code, prompt injection, network calls, or executable scripts. Most findings are false positives from Markdown fences, prompt placeholders, and git SHA labels. The skill remains medium risk because it coordinates subagents that can modify files, run tests, inspect code, and commit changes in a repository.
4
Files scanned
403
Lines analyzed
6
Review items
1
False positives ignored
Capability review items (4)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
The skill directs implementer subagents to implement tasks, write tests, verify changes, and commit work. This is expected for a development workflow, but it can change files and invoke project tooling in the active repository.
The cited prompt text clearly asks subagents to perform implementation, testing, and commits. This is legitimate for the skill purpose, but it creates repository modification risk.
Static external command findings are false positives. The cited sections are Markdown fenced examples and prompt templates, not Ruby or shell backtick execution.
The suspicious characters are Markdown code fences around documentation examples. No executable script, command runner, or interpolation path is present.
Static reconnaissance findings are false positives. The cited lines ask subagents to compare requirements, inspect code, and validate claims; they do not request system or network enumeration.
The wording is a code review checklist. No commands, endpoints, host discovery, port scanning, or credential discovery instructions were found.
Line 107 is an example answer choosing a user-level hook path under ~/.config. It is not a command or automated file access, but it signals possible filesystem interaction when applied to real tasks.
The line is plainly part of a documentation example, not active code. The path is still relevant because the workflow may ask subagents to edit user-level configuration during real tasks.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Static analyzer flagged 38 patterns but all are false positives. DOT diagram syntax (backticks), markdown formatting (crypto patterns), and self-review checklists (reconnaissance patterns) were incorrectly identified. No actual security risks exist - this is a legitimate workflow orchestration skill.
4
Files scanned
403
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.