Skip to content
Report library
Purpose / Other

Caveman Review Skill Security Audit

What the author says it does (original text)

>

Independent security check

No obvious risks found in this check

Files checked
2
Risks found
0
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.No risks found
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

4 instruction sections

The Skill compresses code-review findings into one-line comments containing a location, problem, and proposed fix, with optional severity prefixes.

View source
SKILL.md:8In the instructionsOpen original file
Write code review comments terse and actionable. One line per finding. Location, problem, fix. No throat-clearing.
SKILL.md:12In the instructionsOpen original file
**Format:** `L<line>: <problem>. <fix>.` — or `<file>:L<line>: ...` when reviewing multi-file diffs.
SKILL.md:14In the instructionsOpen original file
**Severity prefix (optional, when mixed):**- `🔴 bug:` — broken behavior, will cause incident- `🟡 risk:` — works but fragile (race, missing null check, swallowed error)- `🔵 nit:` — style, naming, micro-optim. Author can ignore- `❓ q:` — genuine question, not a suggestion

For security findings, architectural disagreements, and onboarding situations, the Skill instructs the reviewer to suspend terse mode and provide a normal explanatory paragraph.

View source
SKILL.md:49In the instructionsOpen original file
Drop terse mode for: security findings (CVE-class bugs need full explanation + reference), architectural disagreements (need rationale, not just a one-liner), and onboarding contexts where the author is new and needs the "why". In those cases write a normal paragraph, then resume terse for the rest.

Its stated boundary is generating paste-ready review comments only; it does not modify code, run linters, or approve or request changes on the user's behalf.

View source
SKILL.md:53In the instructionsOpen original file
Reviews only — does not write the code fix, does not approve/request-changes, does not run linters. Output the comment(s) ready to paste into the PR. "stop caveman-review" or "normal mode": revert to verbose review style.
README.md:11In the instructionsOpen original file
Output only — does not approve, request changes, or run linters.
Start here · InstructionsSKILL.md
caveman-review
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.

File reference map

References: 1
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records2 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • README.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • README.mdSupporting file
  • SKILL.mdInstructions
Lines read
87
File checksum (to compare versions)
0daf53dbe8e8dea59d3a513b7dd8a827fd2e1cb4b40cb38b8f852f25ab1a1afb