T09 · Insecure Skill Coding Practices
- Location
` reference. | Safe | | **C3** Archive aged-out content | Move old diary entries, superseded milestones, and historical promoted entries to a dedicated archive directory. | Safe | ``` ### Technical Analysis The Skill uses its own “Safe” classification to permit changes without explicit user approval. However, several actions classified as safe are state-changing operations rather than read-only optimizations. They can include: - Changing the model assigned to an automated task. - Rewriting task prompts a ...[truncated 3085 chars]:50- Finding
Operational and Memory Files May Be Modified Without Explicit User Approval
- Content
View full analysis
⚠️ **User confirmation gate**: Techniques marked **Moderate** or **High** risk > involve config changes, profile switches, or task merging. Before applying them, > present the proposed change using this template and get explicit approval: > > ``` > ## Proposed Change > **Technique**: [category/technique name] > **Target**: [file/config path] > **Before**: [current state, chars/tokens if measurable] > **After**: [proposed state, estimated savings] > **Risk**: [Moderate/High] > **Rollback**: [how to undo] > ``` > > Techniques marked **Safe** can be applied directly. ``` `SKILL.md:267-285`: ```markdown | **A3** Constrain output | Add "Answer concisely in ≤3 lines" or equivalent to reduce generated tokens. | Safe | | **A4** Remove redundancy | Delete "What NOT to do" sections — proper instructions make negatives implicit. | Safe | | **A5** Reference > inline | Replace full instructions for sub-tasks with file references ("See X.md") ...[truncated 3975 chars]- Remediation
View remediation
