Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
56 changes: 56 additions & 0 deletions auditor/audits/calesthio-OpenMontage.findings.jsonl

Large diffs are not rendered by default.

210 changes: 210 additions & 0 deletions auditor/audits/calesthio-OpenMontage.md

Large diffs are not rendered by default.

3 changes: 2 additions & 1 deletion auditor/disagreements.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -228,9 +228,10 @@
{"event":"maintainer_rejected","pr":"laolaoshiren/claude-code-skills-zh#16","fingerprints":["sha256:c949f71c4d1fa09e8c29690639cfb7dab79feca91ef138b5b9ad7628b062a60c","sha256:fa5e9803f2ff3c1a834b85059c9727fc819a7d7316103668c27e40df2e83e529"],"rule_ids":["SEC-temp-file-write","SEC-temp-file-write"],"dissent_type":"context_missed","quote":"We did not adopt the repository .tmp scheme because new directory might still be 0755 under common POSIX umask.","commenter_role":"maintainer","classifier_model":"haiku-4-5","classifier_confidence":"medium","comments_hash":"sha256:021cf038186b23b9ec71e4fb392a3cc2909e331a4dbdc68aaefdb954c966f75f","timestamp":"2026-08-01T04:40:35Z"}
{"event": "downstream_suppression", "timestamp": "2026-08-02T00:22:26Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R31", "suppression_type": "threshold_adjustment", "fingerprint": "sha256:479c2103b7d8dd2532b6af6c514e5d3b95f364db6503416633bba4b838612fde", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"threshold": 900}, "reason_given": ""}
{"event": "downstream_suppression", "timestamp": "2026-08-02T00:22:26Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R51", "suppression_type": "rule_override", "fingerprint": "sha256:6eb255100e953a537daab93747608eb544524e9e41b5c095b0cafe48079486a2", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"enabled": true, "vocabulary_skill": "skills/cc-suite/vocabulary/"}, "reason_given": ""}
{"event":"maintainer_rejected","timestamp":"2026-05-11T08:06:24Z","issue":"mattpocock/skills#164","comments_hash":"sha256:7a48000517e1a50fdd65730feaeaaffd721e5dab3f21317b0093f6120b01dd26","fingerprints":["sha256:47d7204a0193be04e7009f86d5b457cdaebebf474e8334c46a015c1581add38c"],"rule_ids":["BUG-missing-manifest-entry"],"dissent_type":"intentional_pattern","quote":"Yep, this is intentional","commenter_role":"maintainer","classifier_model":"manual-backfill","classifier_confidence":"high"}
{"event":"self_false_positive","timestamp":"2026-08-05T07:15:24Z","repo":"calesthio/OpenMontage","fingerprint":"sha256:0b9f3d22e6a8dcdb0bdebfb293e379b9ad87bb1b36c78203f5d769f7b9e6b747","rule_id":"CC-orphan-component","reason":"No broken references were found caused by this asymmetry; likely intentional per-tool scoping rather than a defect","rule_gap":"Rule should distinguish intentional tool-scoped skill subsets from accidental omission before flagging"}
{"event": "downstream_suppression", "timestamp": "2026-08-09T00:08:14Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R31", "suppression_type": "threshold_adjustment", "fingerprint": "sha256:479c2103b7d8dd2532b6af6c514e5d3b95f364db6503416633bba4b838612fde", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"threshold": 900}, "reason_given": ""}
{"event": "downstream_suppression", "timestamp": "2026-08-09T00:08:14Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R51", "suppression_type": "rule_override", "fingerprint": "sha256:6eb255100e953a537daab93747608eb544524e9e41b5c095b0cafe48079486a2", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"enabled": true, "vocabulary_skill": "skills/cc-suite/vocabulary/"}, "reason_given": ""}
{"event":"maintainer_rejected","timestamp":"2026-05-11T08:06:24Z","issue":"mattpocock/skills#164","comments_hash":"sha256:7a48000517e1a50fdd65730feaeaaffd721e5dab3f21317b0093f6120b01dd26","fingerprints":["sha256:47d7204a0193be04e7009f86d5b457cdaebebf474e8334c46a015c1581add38c"],"rule_ids":["BUG-missing-manifest-entry"],"dissent_type":"intentional_pattern","quote":"Yep, this is intentional","commenter_role":"maintainer","classifier_model":"manual-backfill","classifier_confidence":"high"}
{"event":"pr_comments_snapshot","timestamp":"2026-08-09T12:20:10Z","pr":"Vincentwei1021/video-shotcraft#30","pr_state":"closed_unmerged","comments_hash":"sha256:ec684af332a7e164a92c9152d3eae3cd9bb7e25b0bd4f6a3b9104ab458675d11","fingerprints":["sha256:fe9bcce17b04db042b1843e383c797e9f8c507d99e5377e649272db1bbf664c5","sha256:feb1039c429e3ace708ddb25e1cb7d9238d2c588b33843a9785be78a245d7a57"],"rule_ids":["SEC-unescaped-attribute-interpolation","SEC-unescaped-attribute-interpolation"],"comments":[{"id":"IC_kwDOTdLZdc8AAAABN8kmRA","author":{"login":"Vincentwei1021"},"authorAssociation":"OWNER","body":"Good catch, and thanks for the clean report — the reproduction made it easy to verify. This was a real injection surface in `mediaMarkup()`.\n\nClosing as already fixed rather than merging: this finding reached us during the review rounds of #27, and the identical fix (wrapping both `data-src` interpolations with `escapeHtml`, plus a CI gate that enforces a canonical `./media/<name>.mp4?v=N` shape for every media URL in `library.json`) landed on `main` with that PR. Your branch's `gallery/app.js` is now byte-identical to `main`, so there's nothing left for this PR to change.\n\nAppreciated nonetheless — the other two NLPM PRs (#28, #31) are merged.","createdAt":"2026-08-09T09:53:03Z","includesCreatedEdit":false,"isMinimized":false,"minimizedReason":"","reactionGroups":[],"url":"https://github.com/Vincentwei1021/video-shotcraft/pull/30#issuecomment-5230896708","viewerDidAuthor":false}]}
{"event":"pr_comments_snapshot","timestamp":"2026-08-12T08:35:47Z","pr":"arpitg1304/robotics-agent-skills#7","pr_state":"closed_unmerged","comments_hash":"sha256:b1651720b2cd332ad12cea643806228d280a8a16ac2ce509a98a58ecb588208e","fingerprints":[],"rule_ids":[],"comments":[{"id":"IC_kwDORZiS988AAAABOZO3ig","author":{"login":"arpitg1304"},"authorAssociation":"OWNER","body":"Superseded by #6, which made this exact change to `skills/ros1/SKILL.md` along with the matching `ros2` fix, and is now merged as 0d2a4da. `main` already carries `name: ros1`.\n\nThanks for catching this one — the mismatch meant the skill silently failed to load, and `ros1`/`ros2` are both in the default bundle in `install.sh`, so it was affecting the out-of-the-box install. Closing as redundant, not as rejected; the fix is in.\n\nSeparately, #9 is a genuinely destructive bug and is still open — I'll pick that up next.","createdAt":"2026-08-12T01:18:29Z","includesCreatedEdit":false,"isMinimized":false,"minimizedReason":"","reactionGroups":[],"url":"https://github.com/arpitg1304/robotics-agent-skills/pull/7#issuecomment-5260949386","viewerDidAuthor":false}]}
{"event":"pr_comments_snapshot","timestamp":"2026-08-12T08:35:48Z","pr":"arpitg1304/robotics-agent-skills#8","pr_state":"closed_unmerged","comments_hash":"sha256:4c48637ab974a68e318ea0f24c230769d9bbc02428279dd2132e06d1728c5a16","fingerprints":[],"rule_ids":[],"comments":[{"id":"IC_kwDORZiS988AAAABOZO7Sg","author":{"login":"arpitg1304"},"authorAssociation":"OWNER","body":"Superseded by #6, which made this exact change to `skills/ros2/SKILL.md` along with the matching `ros1` fix, and is now merged as 0d2a4da. `main` already carries `name: ros2`.\n\nThanks for catching this — same note as on #7: the mismatch stopped the skill loading entirely, and `ros2` ships in the default `install.sh` bundle. Closing as redundant, not as rejected.\n\nSeparately, #9 is a genuinely destructive bug and is still open — I'll pick that up next.","createdAt":"2026-08-12T01:18:39Z","includesCreatedEdit":false,"isMinimized":false,"minimizedReason":"","reactionGroups":[],"url":"https://github.com/arpitg1304/robotics-agent-skills/pull/8#issuecomment-5260950346","viewerDidAuthor":false}]}
Expand Down
Loading
Loading