Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md For each input `SKILL.md`, compiler generates sibling artifacts:
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local skill-artifact compiler with no bundled executable code, network use, or secret handling, though users should be aware it can read skill files under a chosen skills directory when run.
Install only if you want a local compiler for skill files. Review or supply the referenced scripts before relying on it, and avoid enabling the generic execute trigger unless your runtime restricts it to explicit skill invocations.
Referenced artifact was not completely inspected
For each input `SKILL.md`, compiler generates sibling artifacts:
Referenced artifact was not completely inspected
For each input `SKILL.md`, compiler generates sibling artifacts:
Referenced artifact was not completely inspected
For each input `SKILL.md`, compiler generates sibling artifacts:
Referenced artifact was not completely inspected
- `SKILL.struct.json` (canonical runtime structure)
Referenced artifact was not completely inspected
- `SKILL.struct.json` (canonical runtime structure)
Using the generic trigger word "execute" creates a realistic risk of accidental skill invocation because it overlaps with normal user phrasing. In an agent ecosystem, unintended activation can cause commands or follow-on actions to run in contexts where the user did not explicitly mean to invoke this skill.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
"headings": [
{
"level": 2,
"name": "name: skill-compiler\ndescription: Compile SKILL.md files into runtime artifacts (SKILL.struct.json and SKILL.toon), verify freshness/health, and prepare portable publish-ready skill folders for ClawHub-style registries.\ncontract_version: v0\nquick_cmd: skills/public/skill-compiler/scripts/compile-skill --skill skills/todoist/SKILL.md\nrisk_level: safe\ncapabilities:\nbins: [bash, mdquery, jq, toon]\nnetwork: false\nsecrets: []\ndry_run_cmd: skills/public/skill-compiler/scripts/check-env\ncompat:\nos: [linux, macos]\narch: [x64, arm64]\nshell: [bash]\nowner: matt\nlast_tested: 2026-03-08\nrollback: remove skills/public/skill-compiler and revert commit\ncategory: ops\ninputs_min: []\ncost_hint: low",
"text": ""
},
{
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
"headings": [
{
"level": 2,
"name": "name: skill-compiler\ndescription: Compile SKILL.md files into runtime artifacts (SKILL.struct.json and SKILL.toon), verify freshness/health, and prepare portable publish-ready skill folders for ClawHub-style registries.\ncontract_version: v0\nquick_cmd: skills/public/skill-compiler/scripts/compile-skill --skill skills/todoist/SKILL.md\nrisk_level: safe\ncapabilities:\nbins: [bash, mdquery, jq, toon]\nnetwork: false\nsecrets: []\ndry_run_cmd: skills/public/skill-compiler/scripts/check-env\ncompat:\nos: [linux, macos]\narch: [x64, arm64]\nshell: [bash]\nowner: matt\nlast_tested: 2026-03-08\nrollback: remove skills/public/skill-compiler and revert commit\ncategory: ops\ninputs_min: []\ncost_hint: low",
"text": ""
},
{
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
"headings": [
{
"level": 2,
"name": "name: skill-compiler\ndescription: Compile SKILL.md files into runtime artifacts (SKILL.struct.json and SKILL.toon), verify freshness/health, and prepare portable publish-ready skill folders for ClawHub-style registries.\ncontract_version: v0\nquick_cmd: skills/public/skill-compiler/scripts/compile-skill --skill skills/todoist/SKILL.md\nrisk_level: safe\ncapabilities:\nbins: [bash, mdquery, jq, toon]\nnetwork: false\nsecrets: []\ndry_run_cmd: skills/public/skill-compiler/scripts/check-env\ncompat:\nos: [linux, macos]\narch: [x64, arm64]\nshell: [bash]\nowner: matt\nlast_tested: 2026-03-08\nrollback: remove skills/public/skill-compiler and revert commit\ncategory: ops\ninputs_min: []\ncost_hint: low",
"text": ""
},
{
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
"headings": [
{
"level": 2,
"name": "name: skill-compiler\ndescription: Compile SKILL.md files into runtime artifacts (SKILL.struct.json and SKILL.toon), verify freshness/health, and prepare portable publish-ready skill folders for ClawHub-style registries.\ncontract_version: v0\nquick_cmd: skills/public/skill-compiler/scripts/compile-skill --skill skills/todoist/SKILL.md\nrisk_level: safe\ncapabilities:\nbins: [bash, mdquery, jq, toon]\nnetwork: false\nsecrets: []\ndry_run_cmd: skills/public/skill-compiler/scripts/check-env\ncompat:\nos: [linux, macos]\narch: [x64, arm64]\nshell: [bash]\nowner: matt\nlast_tested: 2026-03-08\nrollback: remove skills/public/skill-compiler and revert commit\ncategory: ops\ninputs_min: []\ncost_hint: low",
"text": ""
},
{
This is a manifest/JSON-structured file, so vague-trigger review applies. The file presents preferred runtime trigger words as generic command phrases without negative examples or explicit limits on where they are recognized, which could overlap with ordinary instructions to execute something.
No suspicious patterns detected.