Caveman Help Skill Security Audit
What the author says it does (original text)
>
No obvious risks found in this check
- Files checked
- 2
- Risks found
- 0
Inside this skill
This Skill is a one-shot help card: when invoked, it displays reference information and explicitly forbids changing modes, writing flag files, or persisting anything. The provided files contain no scripts or automatic execution steps.
View source
Display this reference card when invoked. One-shot — do NOT change mode, write flag files, or persist anything. Output in caveman style.Prints a cheat sheet of all caveman modes, sibling skills, deactivation triggers, and how to set the default mode via env var or config file. One-shot display — does not flip the active mode, write flag files, or persist anything. Use when you forget the slash commands.The help card documents an environment variable and configuration file that users may set themselves, explaining that they affect the default mode and automatic activation; this Skill does not instruct the agent to make those changes for the user.
View source
**Environment variable** (highest priority):```bashexport CAVEMAN_DEFAULT_MODE=ultra```**Config file** (`~/.config/caveman/config.json`):```json{ "defaultMode": "lite" }```Set `"off"` to disable auto-activation on session start. User can still activate manually with `/caveman`.Resolution: env var > config file > `full`.The Skill requests output in the user's current language with a compressed writing style, while preserving code, commands, and exact error strings unless the user asks for translation.
View source
Keep user's language by default. User write Portuguese → reply Portuguese caveman. Compress the style, not the language. Technical terms, code, commands, commit types, and exact error strings stay verbatim unless user ask for translation.File reference map
References: 1Files and check records2 files
Coverage and gaps
Content covered in each file
These are the source ranges included in this check, not a guarantee that every issue has been resolved.
SKILL.mdFull text includedREADME.mdFull text included
This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.
README.mdSupporting fileSKILL.mdInstructions
Operations mentioned in code and instructions
Run commands
**Environment variable** (highest priority):```bashexport CAVEMAN_DEFAULT_MODE=ultraConnect to websites
Full docs: https://github.com/JuliusBrussee/caveman- Lines read
- 102
- File checksum (to compare versions)
- 81105bb7064a3728a421da0b61e453cd24a94f0f8dc76a8900915bb7d90df6f5