Back to skill

Security audit

Caveman Compress Mode

Security checks for vulnerabilities and agentic risk

Overview

This is a simple communication-style skill that is broadly coherent, with a usability caution because brief-mode triggers are broad and the style persists until turned off.

Install this only if you want a terse assistant style that may stay active after phrases like "be brief" or "less tokens." Use "stop caveman" or "normal mode" to turn it off, and be cautious in contexts where full wording matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad, common-language requests like "be brief" and "less tokens," which can activate the mode unintentionally during normal conversation. Because the mode then persists across future responses, accidental activation can degrade clarity and safety-sensitive communication, especially if users do not realize a persistent behavior change occurred.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill forces a persistent communication mode once triggered and states it remains active indefinitely until the user explicitly disables it. This creates a communication-policy risk because the assistant may continue using compressed, fragmentary language in later contexts where clarity, nuance, or complete safety messaging is important.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.