{"schema_version":1,"workflow_uuid":"760e8bad-5121-11f1-9bc6-00163e2b0d79","workflow_title":"OSV-Scanner — Google's Open-Source Vulnerability Scanner","page_url":"https://tokrepo.com/en/workflows/asset-760e8bad","raw_url":"https://tokrepo.com/raw/asset-760e8bad","metadata_url":"https://tokrepo.com/metadata/asset-760e8bad.json","install_plan_url":"https://api.tokrepo.com/api/v1/tokenboard/workflows/install-plan?uuid=760e8bad-5121-11f1-9bc6-00163e2b0d79&target=codex","agent_metadata":{"asset_kind":"skill","target_tools":["claude_code","codex","gemini_cli"],"install_mode":"single","entrypoint":"OSV-Scanner Overview","risk_profile":{"executes_code":false,"modifies_global_config":false,"requires_secrets":[],"uses_absolute_paths":false,"network_access":false},"dependencies":{"npm":[],"pip":[],"brew":[],"system":[]},"content_hash":"b70ea3ad5cc3b79b4bd2d3d6baac27e9d0fa0b55e8266f7cb39d8ac1780cad86","verification":{"commands":[],"expected_files":["OSV-Scanner Overview"]},"inferred":true},"agent_fit":{"target":"codex","score":98,"status":"native","policy":"allow","why":["target_tools includes codex","asset_kind skill","install_mode single","markdown-only","policy allow","safe markdown-only Codex install","trust established"],"asset_kind":"skill","install_mode":"single"},"trust":{"author_trust_level":"established","verified_publisher":false,"asset_signed_hash":"b70ea3ad5cc3b79b4bd2d3d6baac27e9d0fa0b55e8266f7cb39d8ac1780cad86","signature_status":"hash_only","install_count":0,"report_count":0,"dangerous_capability_badges":[],"review_status":"unreviewed","signals":["author has published assets","content hash available","no dangerous capability badges"]},"provenance":{"owner_uuid":"8a911193-3180-11f1-9bc6-00163e2b0d79","owner_name":"AI Open Source","source_url":"https://tokrepo.com/en/workflows/asset-760e8bad","content_hash":"b70ea3ad5cc3b79b4bd2d3d6baac27e9d0fa0b55e8266f7cb39d8ac1780cad86","visibility":1,"created_at":"2026-05-16 20:19:18","updated_at":"2026-05-16 21:26:53"},"target_adapter":{"target":"codex","adapter":"skill-directory","root":"~/.codex/skills","entrypoint":"SKILL.md","manifest_path":"~/.codex/tokrepo/install-manifest.json","staging_root":"~/.codex/tokrepo/staged/760e8bad-5121-11f1-9bc6-00163e2b0d79","install_modes":["single","bundle","split","stage_only"],"activates_files":true},"install_plan":{"schema_version":2,"target":"codex","asset_uuid":"760e8bad-5121-11f1-9bc6-00163e2b0d79","asset_title":"OSV-Scanner — Google's Open-Source Vulnerability Scanner","source_url":"https://tokrepo.com/en/workflows/asset-760e8bad","install_mode":"single","entrypoint":"OSV-Scanner Overview","preconditions":[{"type":"target_supported","status":"pass","message":"codex install target is supported"},{"type":"install_root","status":"pass","message":"~/.codex/skills for activated skills; ~/.codex/tokrepo/staged for staged assets"},{"type":"target_tool_metadata","status":"pass","message":"metadata allows codex"},{"type":"content_hash","status":"pass","message":"asset metadata includes content_hash"},{"type":"trust_policy","status":"pass","message":"publisher trust level is established"},{"type":"policy_decision","status":"pass","message":"allow for 760e8bad-5121-11f1-9bc6-00163e2b0d79 (single)"}],"actions":[{"type":"write_file","path":"~/.codex/skills/tokrepo-asset-760e8bad/SKILL.md","source_name":"OSV-Scanner Overview","sha256":"b065d08caded281021077cc6dcde18c2d9a2a6447d2941aeb8104ca3eae76f6b","bytes":4354,"risk":{"executes_code":false,"modifies_global_config":false,"requires_secrets":[],"uses_absolute_paths":false,"network_access":false},"if_exists":"overwrite","entrypoint":true}],"policy_decision":{"decision":"allow","requires_confirmation":false,"reasons":["safe markdown-only Codex install"]},"requires_confirmation":false,"rollback":[{"type":"remove_file","path":"~/.codex/skills/tokrepo-asset-760e8bad/SKILL.md"}],"post_verify":[{"type":"file_sha256","path":"~/.codex/skills/tokrepo-asset-760e8bad/SKILL.md","sha256":"b065d08caded281021077cc6dcde18c2d9a2a6447d2941aeb8104ca3eae76f6b"}],"metadata":{"asset_kind":"skill","target_tools":["claude_code","codex","gemini_cli"],"install_mode":"single","entrypoint":"OSV-Scanner Overview","risk_profile":{"executes_code":false,"modifies_global_config":false,"requires_secrets":[],"uses_absolute_paths":false,"network_access":false},"dependencies":{"npm":[],"pip":[],"brew":[],"system":[]},"content_hash":"b70ea3ad5cc3b79b4bd2d3d6baac27e9d0fa0b55e8266f7cb39d8ac1780cad86","verification":{"commands":[],"expected_files":["OSV-Scanner Overview"]},"inferred":true},"agent_fit":{"target":"codex","score":98,"status":"native","policy":"allow","why":["target_tools includes codex","asset_kind skill","install_mode single","markdown-only","policy allow","safe markdown-only Codex install","trust established"],"asset_kind":"skill","install_mode":"single"},"trust":{"author_trust_level":"established","verified_publisher":false,"asset_signed_hash":"b70ea3ad5cc3b79b4bd2d3d6baac27e9d0fa0b55e8266f7cb39d8ac1780cad86","signature_status":"hash_only","install_count":0,"report_count":0,"dangerous_capability_badges":[],"review_status":"unreviewed","signals":["author has published assets","content hash available","no dangerous capability badges"]},"provenance":{"owner_uuid":"8a911193-3180-11f1-9bc6-00163e2b0d79","owner_name":"AI Open Source","source_url":"https://tokrepo.com/en/workflows/asset-760e8bad","content_hash":"b70ea3ad5cc3b79b4bd2d3d6baac27e9d0fa0b55e8266f7cb39d8ac1780cad86","visibility":1,"created_at":"2026-05-16 20:19:18","updated_at":"2026-05-16 21:26:53"},"target_adapter":{"target":"codex","adapter":"skill-directory","root":"~/.codex/skills","entrypoint":"SKILL.md","manifest_path":"~/.codex/tokrepo/install-manifest.json","staging_root":"~/.codex/tokrepo/staged/760e8bad-5121-11f1-9bc6-00163e2b0d79","install_modes":["single","bundle","split","stage_only"],"activates_files":true}}}