skills/eirkkk/winland-android/caveman/Gen Agent Trust Hub

caveman

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill implements a persona for token-efficient communication using regex-based text transformation.
  • [REMOTE_CODE_EXECUTION]: The skill includes Python scripts (scripts/caveman_compressor.py, scripts/caveman_lint.py, scripts/token_savings_estimator.py) designed to be run locally by the agent. Analysis shows these scripts use only Python standard libraries and perform deterministic text processing without network access or unsafe execution patterns.
  • [PROMPT_INJECTION]: The skill contains instructions to maintain a specific persona ('caveman mode'). However, it includes explicit 'Auto-Clarity Exceptions' that instruct the agent to drop the persona for security warnings and irreversible actions, which is a defensive design pattern.
  • [EXTERNAL_DOWNLOADS]: The skill references external documentation and repositories (e.g., Matt Pocock's GitHub, Anthropic documentation, and government plain language sites). All referenced domains are well-known technology services or official organizations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 07:29 AM
Security Audit — agent-trust-hub — caveman