Skip to content

docs(compress): say that /caveman-compress sends the file to the model provider - #1234

Open
jwcastillo wants to merge 1 commit into
JuliusBrussee:mainfrom
jwcastillo:docs/compress-data-disclosure
Open

jwcastillo wants to merge 1 commit into
JuliusBrussee:mainfrom
jwcastillo:docs/compress-data-disclosure

Conversation

@jwcastillo

Copy link
Copy Markdown

The README privacy section says "The skill runs on your machine and sends nothing", and skills/caveman-compress/SKILL.md doesn't mention that scripts/compress.py sends the file's full text to the configured provider: the claude CLI, the Anthropic API, or an OpenAI-compatible endpoint. The code already says this in a comment (SENSITIVE_BASENAME_REGEX: "ships raw bytes to the Anthropic API"), so this PR only brings the docs in line with it.

Changes (docs only, no code):

  • skills/caveman-compress/SKILL.md: the description says the file's text goes to the configured model provider, and a short note under Purpose lists the providers and the existing refusal of secret-looking filenames.
  • plugins/caveman/skills/caveman-compress/SKILL.md: synced byte for byte, the same way sync-skill.yml does.
  • README.md → Privacy: names /caveman-compress as the exception to "sends nothing".

How I found it: a static and semantic pass with NVIDIA SkillSpector v2.12.0 flagged data flow in caveman-compress. I read each finding. The rest are false positives: the "credential access" hits are the code that refuses .env/credentials/.netrc, the env copy is what the subprocess needs, and the "hidden instructions" are the documented nocompress tags. The one real gap was the missing disclosure.

DCO: the commit is signed off.

🤖 Generated with Claude Code

…l provider

The README privacy section says the skill "sends nothing", and the
caveman-compress SKILL.md never mentions that compress.py sends the file's
full text to the configured provider (claude CLI, Anthropic API, or an
OpenAI-compatible endpoint). Say so in the skill description, in a note
under Purpose, and as the exception in the README privacy line.

The plugin copy of SKILL.md is synced byte for byte, as sync-skill.yml does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Wen <jwcastillo@gmail.com>

Copy link
Copy Markdown
Owner

Reviewed — needs one change, then it's @JuliusBrussee's to accept. The disclosure is accurate and worth having; this is not a correctness objection.

The one blocker: the PR edits both skills/caveman-compress/SKILL.md and plugins/caveman/skills/caveman-compress/SKILL.md. Only the first is a source of truth — .github/workflows/sync-skill.yml copies skills/caveman-compress/ into that mirror on every push to main, so the second edit gets overwritten and should be dropped from the diff. Same note #1200 got; it's an easy trap in this tree.

I verified the claim rather than taking it on trust: /caveman-compress does send the file's text to the configured provider, and the secret-filename refusal happens before the read, so both halves of your warning hold.

Not adopted into #1196: a disclosure/wording change has no failing test behind it, and this routine only ships fixes it can demonstrate. The README Privacy edit reads fine to me and touches no benchmark number, but the skill description is what competes for activation across every installed agent, so the final wording is the maintainer's call.


Generated by Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants