# Security Audit Report — akka

- **Report ID:** `f4acb164-d06e-43ac-804d-a9f999f6cbc4`
- **Generated:** 2026-07-29T06:06:15.511508+00:00
- **Signature:** unsigned (cosign keyless signing runs in CI; Req 22.4)

## 1. Executive Summary

**Badge:** Unsafe (composite)  
**Security score:** 51.38

| Scanner | Badge |
| --- | --- |
| agent-audit-kit | Unsafe |
| agentshield | unavailable |
| cisco-skill-scanner | Unsafe |
| nerlo-behavioral | Verified |
| nerlo-install-instruction | Unsafe |
| nerlo-multi-source | unavailable |
| osv-scanner | unavailable |
| trivy | unavailable |
| trivy_image | unavailable |

| Severity | Findings |
| --- | --- |
| critical | 0 |
| high | 7 |
| medium | 6 |
| low | 21 |

akka is NOT recommended for integration: the scan surfaced 0 critical and 7 high-severity findings. Treat the Per-Scanner Detail section as a remediation worklist and re-scan before reconsidering.

## 2. Source Provenance

- **Repository:** https://github.com/akka/ai-marketplace
- **Commit scanned:** `unknown`
- **License:** unknown
- **Maintainer:** unknown
- **Version:** 2.5.0

## 3. Per-Scanner Detail

### agentshield (v1.4.0) — unavailable / n/a

No findings.

### cisco-skill-scanner (v2.0.11) — Unsafe / 40.5

- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-deploy/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-converge/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-inspect/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-review/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-reliability/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-build/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-tasks/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-specify/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-clarify/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-setup/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/skills/akka-setup/SKILL.md:1)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-plan/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-implement/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-analyze/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-checklist/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-issues/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/skills/akka-constitution/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-deploy/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-review/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-build/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-tasks/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-specify/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-sdd/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-clarify/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-plan/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-implement/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-analyze/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-checklist/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/skills/akka-issues/SKILL.md:None)
- **[low] Skill package contains many files** — Skill package contains 104 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content. (/repo/.:None)
- **[low] Hidden data file detected** — Hidden file found: .agents/plugins/marketplace.json. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.agents/plugins/marketplace.json:None)
- **[low] Hidden data file detected** — Hidden file found: .codex-plugin/plugin.json. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/.codex-plugin/plugin.json:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/commands/akka/setup.toml:1)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka-specify/commands/setup.md:1)
- **[low] Hidden data file detected** — Hidden file found: plugins/akka/.codex-plugin/plugin.json. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/plugins/akka/.codex-plugin/plugin.json:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka/commands/setup.md:1)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/skills/akka-setup/SKILL.md:1)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/plugins/akka-specify/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka-specify/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka-specify/commands/setup.md:1)
- **[low] Hidden data file detected** — Hidden file found: .codex-plugin/plugin.json. Hidden files may contain concealed configuration or data that should be reviewed. (/repo/plugins/akka/.codex-plugin/plugin.json:None)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/plugins/akka/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka/commands/setup.md:1)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka-specify/commands/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka-specify/commands/SKILL.md:1)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka-specify/commands/setup.md:1)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/plugins/akka-specify/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka-specify/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/commands/SKILL.md:None)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka/commands/SKILL.md:1)
- **[low] Dangerous data flow in command pipeline** — Pipeline downloads data from the network and executes it: 'curl -s "https://get.sdkman.io" \| bash'. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.) (/repo/plugins/akka/commands/setup.md:1)
- **[low] Vague skill description** — Skill description is too short (16 chars). Provide detailed explanation. (/repo/plugins/akka/templates/SKILL.md:None)
- **[informational] Skill does not specify a license** — Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms. (/repo/plugins/akka/templates/SKILL.md:None)

### agent-audit-kit (v0.3.26) — Unsafe / 45.0

- **[medium] MCP server command uses relative path** — The command uses a relative path that can be hijacked via PATH manipulation. (plugins/akka/.mcp.json:3)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:9)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.claude-plugin/marketplace.json:15)
- **[high] Unsigned marketplace.json manifest** — .claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection. (.agents/plugins/marketplace.json:8)
- **[medium] Third-party GitHub Action not pinned by full commit SHA** — A workflow in '.github/workflows/' uses a third-party Action ('owner/action@ref') where 'ref' is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision — the downstream repo consuming it will happily run the new code with 'GITHUB_TOKEN' and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy. (.github/workflows/version-bump.yml:35)

### nerlo-behavioral (v0.1.0) — Verified / 100.0

No findings.

### nerlo-install-instruction (v0.1.0) — Unsafe / 20.0

- **[high] opt.nerlo-rules.nerlo-install-pipe-to-shell** — Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... \| bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders — the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal. (/repo/commands/akka/setup.toml:84)
- **[medium] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. "run resource.txt", "execute install.sh", "double-click setup.exe"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected — opaque bundled executables directed by docs warrant review. (/repo/commands/akka/setup.toml:190)
- **[high] opt.nerlo-rules.nerlo-install-pipe-to-shell** — Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... \| bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders — the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal. (/repo/plugins/akka-specify/commands/setup.md:85)
- **[medium] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. "run resource.txt", "execute install.sh", "double-click setup.exe"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected — opaque bundled executables directed by docs warrant review. (/repo/plugins/akka-specify/commands/setup.md:191)
- **[high] opt.nerlo-rules.nerlo-install-pipe-to-shell** — Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... \| bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders — the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal. (/repo/plugins/akka/commands/setup.md:94)
- **[medium] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. "run resource.txt", "execute install.sh", "double-click setup.exe"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected — opaque bundled executables directed by docs warrant review. (/repo/plugins/akka/commands/setup.md:200)
- **[high] opt.nerlo-rules.nerlo-install-pipe-to-shell** — Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... \| bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders — the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal. (/repo/skills/akka-setup/SKILL.md:82)
- **[medium] opt.nerlo-rules.nerlo-install-run-bundled-artifact** — Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. "run resource.txt", "execute install.sh", "double-click setup.exe"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected — opaque bundled executables directed by docs warrant review. (/repo/skills/akka-setup/SKILL.md:188)

### nerlo-multi-source (v0.1.0) — unavailable / n/a

No findings.

### trivy (v0.71.0) — unavailable / n/a

No findings.

### osv-scanner (v2.3.8) — unavailable / n/a

No findings.

### trivy_image (v0.71.0) — unavailable / n/a

No findings.

## 4. Threat Model

Threat model synthesis has not yet run for this scan. This section is generated by the registry's LLM pipeline (Req 22.3) and will appear in the next regeneration of this report.

## 5. Audit Chain

- **Scan job:** `0cf0598b-9d0f-4d45-9efc-5311ddb9e8c8`
- **Completed:** 2026-07-28T21:13:42.637939+00:00
- **Scanner base image:** `us-central1-docker.pkg.dev/nerlo-vsk-prod/nerlo/scanner-base@sha256:86a3d299a4356dfd5a34cd31cfa9f4c28d236d387691f7c8070086afe5224516`
- **AI decision log entries:** 2
  - `e335ae8b-73a3-4bf1-90d0-0b3f7d10a45d`
  - `492f343c-e679-4737-91f4-883bd10ada78`

## 6. Appendix — Raw Scanner Output

```json
[
  {
    "scanner_name": "agentshield",
    "scanner_version": "1.4.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.4382868919929024,
    "status": "not_applicable",
    "examined": null,
    "metadata": {
      "source": "npm",
      "source_url": "https://www.npmjs.com/package/ecc-agentshield",
      "install_command": "npm install -g ecc-agentshield@1.4.0",
      "scans_performed": []
    },
    "display_score": null,
    "display_badge": "unavailable"
  },
  {
    "scanner_name": "cisco-skill-scanner",
    "scanner_version": "2.0.11",
    "score": 40.5,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-deploy/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-converge/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-inspect/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-review/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-reliability/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-build/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-tasks/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-specify/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-clarify/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-setup/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/skills/akka-setup/SKILL.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-plan/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-implement/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-analyze/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-checklist/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-issues/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/skills/akka-constitution/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-deploy/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-review/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-build/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-tasks/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-specify/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-sdd/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-clarify/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-plan/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-implement/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-analyze/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-checklist/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/skills/akka-issues/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "policy_violation",
        "file_path": "/repo/.",
        "line_number": null,
        "rule_identifier": "EXCESSIVE_FILE_COUNT",
        "title": "Skill package contains many files",
        "description": "Skill package contains 104 files. Large file counts increase attack surface and may indicate bundled dependencies or unnecessary content.",
        "remediation": "Review file inventory and remove unnecessary files."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.agents/plugins/marketplace.json",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .agents/plugins/marketplace.json. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/.codex-plugin/plugin.json",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .codex-plugin/plugin.json. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/commands/akka/setup.toml",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka-specify/commands/setup.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/plugins/akka/.codex-plugin/plugin.json",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: plugins/akka/.codex-plugin/plugin.json. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka/commands/setup.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/skills/akka-setup/SKILL.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/plugins/akka-specify/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka-specify/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka-specify/commands/setup.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "obfuscation",
        "file_path": "/repo/plugins/akka/.codex-plugin/plugin.json",
        "line_number": null,
        "rule_identifier": "HIDDEN_DATA_FILE",
        "title": "Hidden data file detected",
        "description": "Hidden file found: .codex-plugin/plugin.json. Hidden files may contain concealed configuration or data that should be reviewed.",
        "remediation": "Move file to a visible location or document its purpose."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/plugins/akka/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka/commands/setup.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka-specify/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka-specify/commands/SKILL.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka-specify/commands/setup.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/plugins/akka-specify/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka-specify/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/commands/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka/commands/SKILL.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "command_injection",
        "file_path": "/repo/plugins/akka/commands/setup.md",
        "line_number": 1,
        "rule_identifier": "PIPELINE_TAINT_FLOW",
        "title": "Dangerous data flow in command pipeline",
        "description": "Pipeline downloads data from the network and executes it: `curl -s \"https://get.sdkman.io\" | bash`. This is a remote code execution pattern. (Note: uses a well-known installer URL - likely a standard installation command.)",
        "remediation": "Review the command pipeline. Avoid piping sensitive data to network commands or shell execution."
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "low",
        "category": "social_engineering",
        "file_path": "/repo/plugins/akka/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "SOCIAL_ENG_VAGUE_DESCRIPTION",
        "title": "Vague skill description",
        "description": "Skill description is too short (16 chars). Provide detailed explanation.",
        "remediation": "Provide a clear, detailed description of what the skill does and when to use it"
      },
      {
        "tool_name": "cisco-skill-scanner",
        "severity": "informational",
        "category": "policy_violation",
        "file_path": "/repo/plugins/akka/templates/SKILL.md",
        "line_number": null,
        "rule_identifier": "MANIFEST_MISSING_LICENSE",
        "title": "Skill does not specify a license",
        "description": "Skill manifest does not include a 'license' field. Specifying a license helps users understand usage terms.",
        "remediation": "Add 'license' field to SKILL.md frontmatter (e.g., MIT, Apache-2.0)"
      }
    ],
    "execution_duration_seconds": 40.024122955001076,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/cisco-ai-skill-scanner/2.0.11/",
      "report_type": "cisco-skill-sast",
      "analyzers_used": [
        "bytecode",
        "pipeline",
        "static_analyzer"
      ],
      "skills_scanned": [
        "akka-deploy",
        "akka-converge",
        "akka-inspect",
        "akka-review",
        "akka-reliability",
        "akka-build",
        "akka-tasks",
        "akka-specify",
        "akka-clarify",
        "akka-setup",
        "akka-plan",
        "akka-implement",
        "akka-analyze",
        "akka-checklist",
        "akka-issues",
        "akka-constitution",
        "akka-deploy",
        "akka-review",
        "akka-build",
        "akka-tasks",
        "akka-specify",
        "akka-sdd",
        "akka-clarify",
        "akka-plan",
        "akka-implement",
        "akka-analyze",
        "akka-checklist",
        "akka-issues",
        "repo",
        "akka-specify",
        "akka",
        "commands",
        "templates",
        "commands",
        "templates"
      ],
      "install_command": "pip install --require-hashes -r docker/scanner-base/cisco-skill-scanner/requirements.txt",
      "severity_counts": {
        "low": 21,
        "high": 0,
        "medium": 0,
        "critical": 0,
        "informational": 35
      },
      "artifact_type_policy": "claude_skill"
    },
    "display_score": 40.5,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "agent-audit-kit",
    "scanner_version": "0.3.26",
    "score": 45.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "mcp-config",
        "file_path": "plugins/akka/.mcp.json",
        "line_number": 3,
        "rule_identifier": "AAK-MCP-006",
        "title": "MCP server command uses relative path",
        "description": "The command uses a relative path that can be hijacked via PATH manipulation.",
        "remediation": "Use absolute paths for MCP server executables."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 9,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".claude-plugin/marketplace.json",
        "line_number": 15,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "high",
        "category": "supply-chain",
        "file_path": ".agents/plugins/marketplace.json",
        "line_number": 8,
        "rule_identifier": "AAK-MARKETPLACE-001",
        "title": "Unsigned marketplace.json manifest",
        "description": ".claude-plugin/marketplace.json lacks a signature or integrity hash field. An attacker with write access to the marketplace can replace the plugin bundle with no detection.",
        "remediation": "Add a Sigstore signature or subresource-integrity hash to each plugin entry. Verify on install."
      },
      {
        "tool_name": "agent-audit-kit",
        "severity": "medium",
        "category": "supply-chain",
        "file_path": ".github/workflows/version-bump.yml",
        "line_number": 35,
        "rule_identifier": "AAK-GHA-IMMUTABLE-001",
        "title": "Third-party GitHub Action not pinned by full commit SHA",
        "description": "A workflow in `.github/workflows/` uses a third-party Action (`owner/action@ref`) where `ref` is a tag or branch name instead of a 40-character commit SHA. A repo-takeover of the Action's publisher can re-point the tag to a malicious revision \u2014 the downstream repo consuming it will happily run the new code with `GITHUB_TOKEN` and write permissions. GitHub's April 2026 Security Roadmap ships Immutable Actions and makes SHA pinning the default policy.",
        "remediation": "Repin third-party Actions to a 40-character commit SHA and add a `# v1.2.3`-style trailing comment for humans. First-party Actions under `actions/` and `github/` are exempt (they now ship Immutable Actions). Dependabot will auto-bump SHA pins when `update-type: all` is set."
      }
    ],
    "execution_duration_seconds": 9.293247544002952,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "pypi",
      "source_url": "https://pypi.org/project/agent-audit-kit/0.3.26/",
      "report_type": "agent-audit-kit-sast",
      "files_scanned": 102,
      "install_command": "pip install --require-hashes -r docker/scanner-base/agent-audit-kit/requirements.txt",
      "rules_evaluated": 211,
      "severity_counts": {
        "low": 0,
        "high": 3,
        "medium": 2,
        "critical": 0,
        "informational": 0
      }
    },
    "display_score": 45.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-behavioral",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 44.74351627899159,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-behavioral",
      "ruleset_path": "/opt/nerlo-rules/exfiltration.yaml",
      "files_scanned": 1,
      "ruleset_paths": [
        "/opt/nerlo-rules/exfiltration.yaml",
        "/opt/nerlo-rules/clipboard_exfiltration.yaml",
        "/opt/nerlo-rules/rce_endpoint.yaml",
        "/opt/nerlo-rules/taint_egress.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "merged_invocation": true
    },
    "display_score": 100.0,
    "display_badge": "Verified"
  },
  {
    "scanner_name": "nerlo-install-instruction",
    "scanner_version": "0.1.0",
    "score": 20.0,
    "scanner_badge": "Unsafe",
    "findings": [
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "high",
        "category": "install-instruction-exec",
        "file_path": "/repo/commands/akka/setup.toml",
        "line_number": 84,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "medium",
        "category": "install-instruction-run",
        "file_path": "/repo/commands/akka/setup.toml",
        "line_number": 190,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "high",
        "category": "install-instruction-exec",
        "file_path": "/repo/plugins/akka-specify/commands/setup.md",
        "line_number": 85,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "medium",
        "category": "install-instruction-run",
        "file_path": "/repo/plugins/akka-specify/commands/setup.md",
        "line_number": 191,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "high",
        "category": "install-instruction-exec",
        "file_path": "/repo/plugins/akka/commands/setup.md",
        "line_number": 94,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "medium",
        "category": "install-instruction-run",
        "file_path": "/repo/plugins/akka/commands/setup.md",
        "line_number": 200,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "high",
        "category": "install-instruction-exec",
        "file_path": "/repo/skills/akka-setup/SKILL.md",
        "line_number": 82,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "title": "opt.nerlo-rules.nerlo-install-pipe-to-shell",
        "description": "Documentation instructs piping a downloaded artifact directly into a shell (curl/wget/iwr ... | bash/sh/iex). This is the curl-pipe-bash install shape used by the ClawHub skill droppers and countless malware loaders \u2014 the fetched payload is executed with zero inspection. Confirm this is expected; it is a strong weaponized-documentation signal.",
        "remediation": null
      },
      {
        "tool_name": "nerlo-install-instruction",
        "severity": "medium",
        "category": "install-instruction-run",
        "file_path": "/repo/skills/akka-setup/SKILL.md",
        "line_number": 188,
        "rule_identifier": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "title": "opt.nerlo-rules.nerlo-install-run-bundled-artifact",
        "description": "Documentation instructs running or double-clicking a bundled/opaque artifact (e.g. \"run resource.txt\", \"execute install.sh\", \"double-click setup.exe\"). This is the FakeGit README shape, where the payload ships as a file the docs tell you to run. Verify the artifact is inspectable and expected \u2014 opaque bundled executables directed by docs warrant review.",
        "remediation": null
      }
    ],
    "execution_duration_seconds": 44.752669488007086,
    "status": "complete",
    "examined": null,
    "metadata": {
      "source": "nerlo-original",
      "source_url": "https://github.com/nerlo-ai/nerlo",
      "report_type": "nerlo-install-instruction",
      "ruleset_path": "/opt/nerlo-rules/install_instructions.yaml",
      "files_scanned": 75,
      "ruleset_paths": [
        "/opt/nerlo-rules/install_instructions.yaml",
        "/opt/nerlo-rules/cursor_rules.yaml"
      ],
      "install_command": "pip install 'semgrep==1.97.0'",
      "severity_counts": {
        "low": 0,
        "high": 4,
        "medium": 4,
        "critical": 0,
        "informational": 0
      },
      "merged_invocation": true
    },
    "display_score": 20.0,
    "display_badge": "Unsafe"
  },
  {
    "scanner_name": "nerlo-multi-source",
    "scanner_version": "0.1.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 11.54958458499459,
    "status": "not_applicable",
    "examined": null,
    "metadata": {
      "source": "nerlo-original",
      "per_source": [],
      "report_type": "nerlo-multi-source",
      "diverged_sources": [],
      "published_surfaces_scanned": 0
    },
    "display_score": null,
    "display_badge": "unavailable"
  },
  {
    "scanner_name": "trivy",
    "scanner_version": "0.71.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.6052989849995356,
    "status": "not_applicable",
    "examined": null,
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/aquasecurity/trivy/releases/tag/v0.71.0",
      "report_type": "filesystem-vulnerability",
      "install_command": "curl -sfL -o /tmp/trivy.deb https://github.com/aquasecurity/trivy/releases/download/v0.71.0/trivy_0.71.0_Linux-64bit.deb && echo '<sha256>  /tmp/trivy.deb' | sha256sum -c - && dpkg -i /tmp/trivy.deb",
      "manifests_scanned": []
    },
    "display_score": null,
    "display_badge": "unavailable"
  },
  {
    "scanner_name": "osv-scanner",
    "scanner_version": "2.3.8",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 0.39485615798912477,
    "status": "not_applicable",
    "examined": null,
    "metadata": {
      "source": "github-releases",
      "source_url": "https://github.com/google/osv-scanner/releases/tag/v2.3.8",
      "report_type": "osv-vulnerability",
      "ecosystems_seen": [],
      "install_command": "curl -sfL -o /usr/local/bin/osv-scanner https://github.com/google/osv-scanner/releases/download/v2.3.8/osv-scanner_linux_amd64 && echo '<sha256>  /usr/local/bin/osv-scanner' | sha256sum -c - && chmod +x /usr/local/bin/osv-scanner",
      "manifests_scanned": [],
      "finding_id_aliases": {},
      "cross_scanner_correlation": {
        "only_osv": [],
        "only_trivy": [],
        "intersection_ids": []
      }
    },
    "display_score": null,
    "display_badge": "unavailable"
  },
  {
    "scanner_name": "trivy_image",
    "scanner_version": "0.71.0",
    "score": 100.0,
    "scanner_badge": "Verified",
    "findings": [],
    "execution_duration_seconds": 1.1989992344751954e-05,
    "status": "not_applicable",
    "examined": null,
    "metadata": {
      "reason": "no OCI image acquired for this artifact"
    },
    "display_score": null,
    "display_badge": "unavailable"
  }
]
```
