# Security Audit Report — accessibility-expert

- **Report ID:** `6ca8c093-7011-455b-8663-1dea60a35dd1`
- **Generated:** 2026-08-12T10:46:40.679628+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Unsafe (composite)  
**Security score:** 58.83

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | not_applicable |
| bearer | not_applicable |
| capslock | not_applicable |
| cisco-skill-scanner | Caution |
| govulncheck | not_applicable |
| nerlo-behavioral | not_applicable |
| nerlo-install-instruction | Verified |
| osv-scanner | not_applicable |
| trivy | not_applicable |
| trivy_image | not_applicable |

| Severity | Findings |
| --- | --- |
| critical | 0 |
| high | 28 |
| medium | 9 |
| low | 2 |
| informational | 39 |

accessibility-expert is NOT recommended for integration: the scan surfaced 0 critical and 28 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering.

## 2. Source Provenance

- **Repository:** https://github.com/miaoge-ge/coding-agent-skills
- **Commit scanned:** `unknown`
- **License:** unknown
- **Maintainer:** unknown
- **Version:** unknown

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — not_applicable / n/a

No findings.

### cisco-skill-scanner (v2.0.11) — Caution / 76.5

- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/accessibility-expert/skills/accessibility-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/bash-scripting-expert/skills/bash-scripting-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/typescript-expert/skills/typescript-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/nodejs-backend-expert/skills/nodejs-backend-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/python-expert/skills/python-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/performance-expert/skills/performance-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/api-design-expert/skills/api-design-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/llm-testing-expert/skills/llm-testing-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/competitive-programming-expert/skills/competitive-programming-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/refactoring-expert/skills/refactoring-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/rust-expert/skills/rust-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/cpp-expert/skills/cpp-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/tailwind-expert/skills/tailwind-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-geometry/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-postprocessing/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-materials/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-interaction/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-lighting/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-animation/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-loaders/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-textures/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-fundamentals/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/threejs/skills/threejs-shaders/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/react-expert/skills/react-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/prompt-engineering-expert/skills/prompt-engineering-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/docker-expert/skills/docker-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/security-expert/skills/security-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/rag-expert/skills/rag-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/debugging-expert/skills/debugging-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/sql-expert/skills/sql-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/go-expert/skills/go-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/github-master/skills/github-master/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/nextjs-expert/skills/nextjs-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/deep-learning-expert/skills/deep-learning-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/kubernetes-expert/skills/kubernetes-expert/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/software-architect/skills/software-architect/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/testing-expert/skills/testing-expert/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/rules/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/rules/SKILL.md:None)

### agent-audit-kit (v0.3.26) — Unsafe / 0.0

- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:11)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:22)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:33)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:44)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:55)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:66)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:77)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:88)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:100)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:111)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:122)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:133)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:144)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:155)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:166)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:177)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:188)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:199)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:210)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:221)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:232)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:243)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:254)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:265)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:276)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:287)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:298)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:309)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (.claude-plugin/marketplace.json:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/performance-expert/skills/performance-expert/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/llm-testing-expert/skills/llm-testing-expert/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/cpp-expert/.claude-plugin/plugin.json:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/cpp-expert/skills/cpp-expert/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/rag-expert/skills/rag-expert/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/debugging-expert/skills/debugging-expert/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/deep-learning-expert/skills/deep-learning-expert/SKILL.md:None)
- **[medium] Healthcare context without explicit AI-disclosure to user** — Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions. (plugins/software-architect/skills/software-architect/SKILL.md:None)

### bearer (v2.0.2) — not_applicable / n/a

No findings.

### nerlo-behavioral (v0.1.0) — not_applicable / n/a

No findings.

### nerlo-install-instruction (v0.1.0) — Verified / 100.0

No findings.

### capslock (vv0.3.2) — not_applicable / n/a

No findings.

### trivy (v0.71.0) — not_applicable / n/a

No findings.

### osv-scanner (v2.3.8) — not_applicable / n/a

No findings.

### trivy_image (v0.71.0) — not_applicable / n/a

No findings.

### govulncheck (vv1.6.0) — not_applicable / n/a

No findings.

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `b55859da-50e4-4105-8dcd-2ee197784d39`
- **Completed:** 2026-08-12T09:48:29.911993+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:d5aaefa8b517d1f03832091ab094e20dc73160a07ae1102af1b2e395ce6ce852`
- **AI decision log entries:** 2
  - `cfc9c2a6-645a-417e-832f-3d239e358181`
  - `e4e95ac8-3704-40e9-b739-db0ab3edf53d`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.2016035160049796,
    "status": "not_applicable",
    "examined": {
      "unit": "scan_targets",
      "count": 0
    },
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": []
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 76.5,
    "scanner_badge": "Caution",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/accessibility-expert/skills/accessibility-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/bash-scripting-expert/skills/bash-scripting-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/typescript-expert/skills/typescript-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/nodejs-backend-expert/skills/nodejs-backend-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/python-expert/skills/python-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/performance-expert/skills/performance-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/api-design-expert/skills/api-design-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/llm-testing-expert/skills/llm-testing-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/competitive-programming-expert/skills/competitive-programming-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/refactoring-expert/skills/refactoring-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/rust-expert/skills/rust-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/cpp-expert/skills/cpp-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/tailwind-expert/skills/tailwind-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-geometry/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-postprocessing/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-materials/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-interaction/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-lighting/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-animation/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-loaders/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-textures/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-fundamentals/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/threejs/skills/threejs-shaders/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/react-expert/skills/react-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/prompt-engineering-expert/skills/prompt-engineering-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/docker-expert/skills/docker-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/security-expert/skills/security-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/rag-expert/skills/rag-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/debugging-expert/skills/debugging-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/sql-expert/skills/sql-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/go-expert/skills/go-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/github-master/skills/github-master/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/nextjs-expert/skills/nextjs-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/deep-learning-expert/skills/deep-learning-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/kubernetes-expert/skills/kubernetes-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/software-architect/skills/software-architect/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/testing-expert/skills/testing-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/rules/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      }
    ],
    "execution_duration_seconds": 8.430705358972773,
    "status": "complete",
    "examined": {
      "unit": "skills",
      "count": 39
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "accessibility-expert",
        "bash-scripting-expert",
        "typescript-expert",
        "nodejs-backend-expert",
        "python-expert",
        "performance-expert",
        "api-design-expert",
        "llm-testing-expert",
        "competitive-programming-expert",
        "refactoring-expert",
        "rust-expert",
        "cpp-expert",
        "tailwind-expert",
        "threejs-geometry",
        "threejs-postprocessing",
        "threejs-materials",
        "threejs-interaction",
        "threejs-lighting",
        "threejs-animation",
        "threejs-loaders",
        "threejs-textures",
        "threejs-fundamentals",
        "threejs-shaders",
        "react-expert",
        "prompt-engineering-expert",
        "docker-expert",
        "security-expert",
        "rag-expert",
        "debugging-expert",
        "sql-expert",
        "go-expert",
        "github-master",
        "nextjs-expert",
        "deep-learning-expert",
        "kubernetes-expert",
        "software-architect",
        "testing-expert",
        "repo",
        "rules"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 2,
        "high": 0,
        "medium": 0,
        "critical": 0,
        "informational": 39
      },
      "artifact_type_policy": "claude_skill"
    },
    "display_score": 76.5,
    "display_badge": "Caution"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 0.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 11,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 22,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 33,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 44,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 55,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 66,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 77,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 88,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 100,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 111,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 122,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 133,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 144,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 155,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 166,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 177,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 188,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 199,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 210,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 221,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 232,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 243,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 254,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 265,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 276,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 287,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 298,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 309,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/performance-expert/skills/performance-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/llm-testing-expert/skills/llm-testing-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/cpp-expert/.claude-plugin/plugin.json",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/cpp-expert/skills/cpp-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/rag-expert/skills/rag-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/debugging-expert/skills/debugging-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/deep-learning-expert/skills/deep-learning-expert/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "legal-compliance",
        "file_path": "plugins/software-architect/skills/software-architect/SKILL.md",
        "line_number": null,
        "rule_identifier": "AAK-HEALTHCARE-AI-004",
        "title": "Healthcare context without explicit AI-disclosure to user",
        "description": "Text mentions patient / clinical / mental-health / therapy / diagnosis but the tool never explicitly says the responder is an AI. Multiple 2026 state laws (TN, WA, UT) expect clear AI disclosure in clinical interactions.",
        "remediation": "Add a visible 'You are talking to an AI; this is not medical advice and is not a substitute for licensed care' disclosure."
      }
    ],
    "execution_duration_seconds": 1.4045916449977085,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 69
    },
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 0,
        "high": 28,
        "medium": 9,
        "critical": 0,
        "informational": 0
      }
    },
    "display_score": 0.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "bearer",
    "scanner_version": "2.0.2",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.13053354300791398,
    "status": "not_applicable",
    "examined": {
      "unit": "files",
      "count": 0
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/Bearer/bearer",
      "report_type": "security",
      "install_command": "curl -sfL https://raw.githubusercontent.com/Bearer/bearer/main/contrib/install.sh | sh -s -- -b /usr/local/bin \"v2.0.2\"",
      "environment_note": "bearer found no supported-language source files to analyze (see _SUPPORTED_SOURCE_EXTENSIONS); reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute"
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 3.433440872002393,
    "status": "not_applicable",
    "examined": {
      "unit": "files",
      "count": 0
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/exfiltration.yaml",
        "/opt/nerlo-rules/clipboard_exfiltration.yaml",
        "/opt/nerlo-rules/rce_endpoint.yaml",
        "/opt/nerlo-rules/taint_egress.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "merged_invocation": true
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 3.4335835209931247,
    "status": "complete",
    "examined": {
      "unit": "files",
      "count": 40
    },
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "ruleset_paths": [
        "/opt/nerlo-rules/install_instructions.yaml",
        "/opt/nerlo-rules/cursor_rules.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "merged_invocation": true
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "capslock",
    "scanner_version": "v0.3.2",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.13419422000879422,
    "status": "not_applicable",
    "examined": {
      "unit": "packages",
      "count": 0
    },
    "metadata": {
      "source": "go-module-proxy",
      "source_url": "https://github.com/google/capslock/releases/tag/v0.3.2",
      "report_type": "go-capability",
      "vendor_mode": false,
      "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install github.com/google/capslock/cmd/capslock@v0.3.2  # github.com/google/capslock v0.3.2 h1:0ZQa9YR8s9ewFu1g5w6Rgd/lW/4dga7qJew3K6Ql7aM=",
      "environment_note": "capslock found no .go files to analyze; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute",
      "go_files_present": 0,
      "artifact_type_policy": "claude_skill",
      "expected_capabilities": null,
      "artifact_type_explicit": true
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "trivy",
    "scanner_version": "0.71.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.2696149100083858,
    "status": "not_applicable",
    "examined": {
      "unit": "manifests",
      "count": 0
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
      "report_type": "filesystem-vulnerability",
      "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
      "manifests_scanned": []
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "osv-scanner",
    "scanner_version": "2.3.8",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.19776945904595777,
    "status": "not_applicable",
    "examined": {
      "unit": "manifests",
      "count": 0
    },
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
      "report_type": "osv-vulnerability",
      "ecosystems_seen": [],
      "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
      "manifests_scanned": [],
      "finding_id_aliases": {},
      "cross_scanner_correlation": {
        "only_osv": [],
        "only_trivy": [],
        "intersection_ids": []
      }
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "trivy_image",
    "scanner_version": "0.71.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 3.839004784822464e-05,
    "status": "not_applicable",
    "examined": {
      "unit": "image_targets",
      "count": 0
    },
    "metadata": {
      "reason": "no OCI image acquired for this artifact"
    },
    "display_score": null,
    "display_badge": "not_applicable"
  },
  {
    "scanner_name": "govulncheck",
    "scanner_version": "v1.6.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.0917150949826464,
    "status": "not_applicable",
    "examined": {
      "unit": "modules",
      "count": 0
    },
    "metadata": {
      "source": "go-module-proxy",
      "source_url": "https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck",
      "report_type": "go-reachability",
      "vendor_mode": false,
      "go_mod_present": false,
      "install_command": "GOTOOLCHAIN=local GOFLAGS=-mod=mod GOSUMDB=sum.golang.org GOBIN=/usr/local/bin go install golang.org/x/vuln/cmd/govulncheck@v1.6.0  # golang.org/x/vuln v1.6.0 h1:FeMO9Rm/HwyduOztbvKcOw+zvDEPr4I4aQNSfevFcKY=",
      "offline_db_path": "/opt/govulncheck-db",
      "environment_note": "govulncheck found no go.mod, so this tree declares no Go module and no Go dependencies; reported not_applicable rather than a clean 100 \u2014 the scanner never ran, so it has no verdict to contribute"
    },
    "display_score": null,
    "display_badge": "not_applicable"
  }
]
```
