Skip to content
Report library
Purpose / Documents

Doc Coauthoring Skill Security Audit

What the author says it does (original text)

Guide users through a structured workflow for co-authoring documentation. Use when user wants to write documentation, proposals, technical specs, decision docs, or similar structured content. This workflow helps users efficiently transfer context, refine content through iteration, and verify the doc works for readers. Trigger when user mentions writing docs, creating proposals, drafting specs, or

Independent security check

Security risks found

Files checked
1
Risks found
4
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 4
Medium risk

The workflow solicits broad internal organizational information

Source references: 3
What we found

The workflow explicitly requests team dynamics, past incidents, politics, discussion threads, and shared documents, and suggests reading them through connectors. These sources may exceed what the document needs. Once a channel or document is mentioned, the workflow calls for notice rather than per-source scope confirmation.

Why this matters

With connectors enabled, private discussions, personnel relationships, incident history, or unrelated document content could enter model context and drafts, increasing sensitive-data processing and accidental disclosure.

The workflow solicits team dynamics, past incidents, internal politics, channels, and shared documents, and directs the assistant to read mentioned sources when integrations exist. Confirmation is required for searching unknown entities, but not for each already-mentioned channel or document. This can expose confidential or personal material unrelated to the final document. A user can restrict collection to necessary facts and require per-source approval and scope limits.

SKILL.md:56In the instructionsOpen original file
Once initial questions are answered, encourage the user to dump all the context they have. Request information such as:- Background on the project/problem- Related team discussions or shared documents- Why alternative solutions aren't being used- Organizational context (team dynamics, past incidents, politics)- Timeline pressures or constraints- Technical architecture or dependencies- Stakeholder concernsAdvise them not to worry about organizing it - just get it all out. Offer multiple ways to provide context:- Info dump stream-of-consciousness- Point to team channels or threads to read- Link to shared documents**If integrations are available** (e.g., Slack, Teams, Google Drive, SharePoint, or other MCP servers), mention that these can be used to pull in context directly.
Show 2 other places
SKILL.md:76In the instructionsOpen original file
**During context gathering:**- If user mentions team channels or shared documents:  - If integrations available: Inform them the content will be read now, then use the appropriate integration  - If integrations not available: Explain lack of access. Suggest they enable connectors in Claude settings, or paste the relevant content directly.- If user mentions entities/projects that are unknown:  - Ask if connected tools should be searched to learn more  - Wait for user confirmation before searching
SKILL.md:65In the instructionsOpen original file
Advise them not to worry about organizing it - just get it all out. Offer multiple ways to provide context:- Info dump stream-of-consciousness- Point to team channels or threads to read- Link to shared documents**If integrations are available** (e.g., Slack, Teams, Google Drive, SharePoint, or other MCP servers), mention that these can be used to pull in context directly.
Medium risk

Reader testing sends the document to fresh model contexts or sub-agents

Source references: 3
What we found

The automated path gives document content to a fresh sub-agent for each question. The manual path tells the user to paste the document or share a connector-backed link in Claude.ai. The workflow does not first check confidentiality or require minimization and redaction.

Why this matters

Technical specifications, unreleased plans, customer data, credentials, or regulated information could be processed in additional contexts the user did not intend to authorize. A shared link may also expose further connector-accessible material.

The automated path sends document content and each question to a fresh sub-agent. The manual path asks the user to paste the document into a new Claude.ai conversation or share a connected-document link. These steps do not call for a confidentiality check, redaction, or minimum necessary excerpts. Sensitive documents could therefore reach an additional processing context; users can require local-only testing, excerpt-only tests, or prior redaction.

SKILL.md:261In the instructionsOpen original file
### Step 2: Test with Sub-AgentAnnounce that these questions will be tested with a fresh Claude instance (no context from this conversation).For each question, invoke a sub-agent with just the document content and the question.Summarize what Reader Claude got right/wrong for each question.
Show 2 other places
SKILL.md:300In the instructionsOpen original file
### Step 2: Setup TestingProvide testing instructions:1. Open a fresh Claude conversation: https://claude.ai2. Paste or share the document content (if using a shared doc platform with connectors enabled, provide the link)3. Ask Reader Claude the generated questions
SKILL.md:290In the instructionsOpen original file
**If no access to sub-agents (e.g., claude.ai web interface):**The user will need to do the testing manually.### Step 1: Predict Reader QuestionsAsk what questions people might ask when trying to discover this document. What would they type into Claude.ai?Generate 5-10 questions that readers would realistically ask.### Step 2: Setup TestingProvide testing instructions:1. Open a fresh Claude conversation: https://claude.ai2. Paste or share the document content (if using a shared doc platform with connectors enabled, provide the link)3. Ask Reader Claude the generated questions
Medium risk

Linking the co-authoring conversation may expose material excluded from the final document

Source references: 2
What we found

The final tips recommend linking the conversation in an appendix. That conversation may contain rejected options, internal politics, past incidents, personal opinions, and connector-retrieved material that was intentionally omitted from the final document.

Why this matters

People receiving the document could use the link to access broader and more sensitive background than the finished text, potentially including information they should not see.

The final tips suggest linking the collaboration conversation in an appendix, while the workflow earlier encourages that conversation to contain internal politics, past incidents, and other raw context. The suggestion is optional, but it does not require reviewing access permissions or removing sensitive material excluded from the final draft. If the document is shared broadly, the link could expose the wider conversation. Users can omit it or include only a reviewed, redacted summary.

SKILL.md:344In the instructionsOpen original file
**If user wants final review, provide it. Otherwise:**Announce document completion. Provide a few final tips:- Consider linking this conversation in an appendix so readers can see how the doc was developed- Use appendices to provide depth without bloating the main doc- Update the doc as feedback is received from real readers
Show 1 other places
SKILL.md:56In the instructionsOpen original file
Once initial questions are answered, encourage the user to dump all the context they have. Request information such as:- Background on the project/problem- Related team discussions or shared documents- Why alternative solutions aren't being used- Organizational context (team dynamics, past incidents, politics)- Timeline pressures or constraints- Technical architecture or dependencies- Stakeholder concerns
Medium risk

A blanket claim about image visibility may induce unnecessary sensitive-image uploads

Source references: 1
What we found

The workflow states that Claude cannot see images lacking alt text and consequently asks the user to paste every image into chat. Actual visibility depends on the platform and tools, and the instruction does not first assess image sensitivity or explain the processing boundary.

Why this matters

A user may upload architecture diagrams, screenshots, customer records, or images containing secrets even though alt text could have been prepared locally, causing avoidable disclosure.

The workflow asks for consent before generating alt text, so uploading is not mandatory. However, it broadly states that Claude cannot see images lacking alt text and then asks the user to paste every image into chat. Images containing credentials, personal data, or internal interfaces would enter the chat’s processing scope, with no visible instruction to inspect or redact them first. Users can provide a text description instead or crop and mask sensitive areas.

SKILL.md:49In the instructionsOpen original file
**If user mentions editing an existing shared document:**- Use the appropriate integration to read the current state- Check for images without alt-text- If images exist without alt-text, explain that when others use Claude to understand the doc, Claude won't be able to see them. Ask if they want alt-text generated. If so, request they paste each image into chat for descriptive alt-text generation.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

6 instruction sections

The Skill defines a three-stage document workflow: gather context, draft and refine each section, then test it from an independent reader's perspective.

View source
SKILL.md:8In the instructionsOpen original file
This skill provides a structured workflow for guiding users through collaborative document creation. Act as an active guide, walking users through three stages: Context Gathering, Refinement & Structure, and Reader Testing.

Context gathering may read user-mentioned team channels and shared documents; for unknown entities, the workflow requires confirmation before searching connected tools.

View source
SKILL.md:76In the instructionsOpen original file
**During context gathering:**- If user mentions team channels or shared documents:  - If integrations available: Inform them the content will be read now, then use the appropriate integration  - If integrations not available: Explain lack of access. Suggest they enable connectors in Claude settings, or paste the relevant content directly.- If user mentions entities/projects that are unknown:  - Ask if connected tools should be searched to learn more  - Wait for user confirmation before searching

After the structure is agreed, the Skill creates a document with placeholders; without artifact support, it creates a Markdown file in the working directory and modifies it during later iterations.

View source
SKILL.md:130In the instructionsOpen original file
**Once structure is agreed:**Create the initial document structure with placeholder text for all sections.**If access to artifacts is available:**Use `create_file` to create an artifact. This gives both Claude and the user a scaffold to work from.Inform them that the initial structure with placeholders for all sections will be created.Create artifact with all section headers and brief placeholder text like "[To be written]" or "[Content here]".Provide the scaffold link and indicate it's time to fill in each section.**If no access to artifacts:**Create a markdown file in the working directory. Name it appropriately (e.g., `decision-doc.md`, `technical-spec.md`).Inform them that the initial structure with placeholders for all sections will be created.Create file with all section headers and placeholder text.Confirm the filename has been created and indicate it's time to fill in each section.

Reader testing has two paths: when sub-agents are available, document content and questions are passed to fresh agents; otherwise, the user is instructed to paste or share the document in a new Claude.ai conversation.

View source
SKILL.md:261In the instructionsOpen original file
### Step 2: Test with Sub-AgentAnnounce that these questions will be tested with a fresh Claude instance (no context from this conversation).For each question, invoke a sub-agent with just the document content and the question.Summarize what Reader Claude got right/wrong for each question.
SKILL.md:300In the instructionsOpen original file
### Step 2: Setup TestingProvide testing instructions:1. Open a fresh Claude conversation: https://claude.ai2. Paste or share the document content (if using a shared doc platform with connectors enabled, provide the link)3. Ask Reader Claude the generated questions
Start here · InstructionsSKILL.md
doc-coauthoring
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions

Operations mentioned in code and instructions

Connect to websites
SKILL.md:303In the instructionsOpen original file
Provide testing instructions:1. Open a fresh Claude conversation: https://claude.ai2. Paste or share the document content (if using a shared doc platform with connectors enabled, provide the link)
Lines read
376
File checksum (to compare versions)
10aad9b41e16a7db568aca2ac80f517b6ba66478f01be890e305aaa3b2b2dda4