Caveman Evidence Review Skill Security Audit
What the author says it does (original text)
>
No obvious risks found in this check
- Files checked
- 1
- Risks found
- 0
Inside this skill
The Skill defines itself as a read-only review tool and explicitly prohibits starting, approving, canceling, or rolling back experiments.
View source
Act as a read-only operator. Build conclusions from current Caveman data, notfrom repository guesses. Never start, approve, cancel, or roll back anexperiment from this skill.The default review retrieves cost, score, workflow, savings, and trace metadata; prompt, completion, tool, and artifact payloads are excluded unless the user explicitly requests payload review.
View source
Never add or relabel them.2. Do not fetch prompt, completion, tool, or artifact payloads unless the user explicitly asks for payload review. Metadata, spans, timing, models, token counts, status, and optimizer attribution are enough for the default review.3. Scope every read to the project selected by Caveman context. Never supply anCall `caveman_trace_get` for a small number of high-signal trace ids. Inspectrequest and span metadata, latency, status, token counts, cache state, appliedoptimizers, and model route. Keep payload retrieval off.Reads are required to remain within the project selected by Caveman context; if login or project selection is missing, the workflow must stop rather than guess the identity or scope.
View source
counts, status, and optimizer attribution are enough for the default review.3. Scope every read to the project selected by Caveman context. Never supply an organization id.4. Empty results are evidence of no current signal, not zero cost or zero risk.Stop if login or project selection is missing. Ask the user to run`caveman login` or select a project; never guess.Reporting rules separate measured cost, inferred headroom, verified savings, and evidence cost, while requiring bounded time windows and specific trace IDs to avoid presenting aggregate correlation as causation.
View source
1. Keep these buckets separate: - measured provider-complete list-price cost; - `inferred` daily headroom; - `verified` ledger savings; - evidence cost. Never add or relabel them.2. Do not fetch prompt, completion, tool, or artifact payloads unless the user4. Empty results are evidence of no current signal, not zero cost or zero risk.5. Cite trace ids and exact time windows used. Do not claim a cause from an aggregate alone.Files and check records1 files
Coverage and gaps
Content covered in each file
These are the source ranges included in this check, not a guarantee that every issue has been resolved.
SKILL.mdFull text included
This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.
SKILL.mdInstructions
Operations mentioned in code and instructions
Run commands
```bashcaveman cloud whoami```bashcaveman cloud costs```bashcaveman cloud traces search \- Lines read
- 143
- File checksum (to compare versions)
- 2857b90d5d77b9646e02b0cf005f1dcf03002ddc8fc67d1cd9a6659beab3747b