Skip to content
Report library
Purpose / Other

Caveman Evidence Review Skill Security Audit

What the author says it does (original text)

>

Independent security check

No obvious risks found in this check

Files checked
1
Risks found
0
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

6 instruction sections

The Skill defines itself as a read-only review tool and explicitly prohibits starting, approving, canceling, or rolling back experiments.

View source
SKILL.md:11In the instructionsOpen original file
Act as a read-only operator. Build conclusions from current Caveman data, notfrom repository guesses. Never start, approve, cancel, or roll back anexperiment from this skill.

The default review retrieves cost, score, workflow, savings, and trace metadata; prompt, completion, tool, and artifact payloads are excluded unless the user explicitly requests payload review.

View source
SKILL.md:23In the instructionsOpen original file
   Never add or relabel them.2. Do not fetch prompt, completion, tool, or artifact payloads unless the user   explicitly asks for payload review. Metadata, spans, timing, models, token   counts, status, and optimizer attribution are enough for the default review.3. Scope every read to the project selected by Caveman context. Never supply an
SKILL.md:104In the instructionsOpen original file
Call `caveman_trace_get` for a small number of high-signal trace ids. Inspectrequest and span metadata, latency, status, token counts, cache state, appliedoptimizers, and model route. Keep payload retrieval off.

Reads are required to remain within the project selected by Caveman context; if login or project selection is missing, the workflow must stop rather than guess the identity or scope.

View source
SKILL.md:26In the instructionsOpen original file
   counts, status, and optimizer attribution are enough for the default review.3. Scope every read to the project selected by Caveman context. Never supply an   organization id.4. Empty results are evidence of no current signal, not zero cost or zero risk.
SKILL.md:47In the instructionsOpen original file
Stop if login or project selection is missing. Ask the user to run`caveman login` or select a project; never guess.

Reporting rules separate measured cost, inferred headroom, verified savings, and evidence cost, while requiring bounded time windows and specific trace IDs to avoid presenting aggregate correlation as causation.

View source
SKILL.md:17In the instructionsOpen original file
1. Keep these buckets separate:   - measured provider-complete list-price cost;   - `inferred` daily headroom;   - `verified` ledger savings;   - evidence cost.   Never add or relabel them.2. Do not fetch prompt, completion, tool, or artifact payloads unless the user
SKILL.md:29In the instructionsOpen original file
4. Empty results are evidence of no current signal, not zero cost or zero risk.5. Cite trace ids and exact time windows used. Do not claim a cause from an   aggregate alone.
Start here · InstructionsSKILL.md
caveman-evidence-review
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions

Operations mentioned in code and instructions

Run commands
SKILL.md:42In the instructionsOpen original file
```bashcaveman cloud whoami
SKILL.md:65In the instructionsOpen original file
```bashcaveman cloud costs
SKILL.md:92In the instructionsOpen original file
```bashcaveman cloud traces search \
Lines read
143
File checksum (to compare versions)
2857b90d5d77b9646e02b0cf005f1dcf03002ddc8fc67d1cd9a6659beab3747b