Repository navigation
docs(compress): say that /caveman-compress sends the file to the model provider - #1234
jwcastillo wants to merge 1 commit into
Conversation
…l provider The README privacy section says the skill "sends nothing", and the caveman-compress SKILL.md never mentions that compress.py sends the file's full text to the configured provider (claude CLI, Anthropic API, or an OpenAI-compatible endpoint). Say so in the skill description, in a note under Purpose, and as the exception in the README privacy line. The plugin copy of SKILL.md is synced byte for byte, as sync-skill.yml does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Wen <jwcastillo@gmail.com>
|
Reviewed — needs one change, then it's @JuliusBrussee's to accept. The disclosure is accurate and worth having; this is not a correctness objection. The one blocker: the PR edits both I verified the claim rather than taking it on trust: Not adopted into #1196: a disclosure/wording change has no failing test behind it, and this routine only ships fixes it can demonstrate. The README Privacy edit reads fine to me and touches no benchmark number, but the skill Generated by Claude Code |
The README privacy section says "The skill runs on your machine and sends nothing", and
skills/caveman-compress/SKILL.mddoesn't mention thatscripts/compress.pysends the file's full text to the configured provider: theclaudeCLI, the Anthropic API, or an OpenAI-compatible endpoint. The code already says this in a comment (SENSITIVE_BASENAME_REGEX: "ships raw bytes to the Anthropic API"), so this PR only brings the docs in line with it.Changes (docs only, no code):
skills/caveman-compress/SKILL.md: thedescriptionsays the file's text goes to the configured model provider, and a short note under Purpose lists the providers and the existing refusal of secret-looking filenames.plugins/caveman/skills/caveman-compress/SKILL.md: synced byte for byte, the same waysync-skill.ymldoes.README.md→ Privacy: names/caveman-compressas the exception to "sends nothing".How I found it: a static and semantic pass with NVIDIA SkillSpector v2.12.0 flagged data flow in
caveman-compress. I read each finding. The rest are false positives: the "credential access" hits are the code that refuses.env/credentials/.netrc, the env copy is what the subprocess needs, and the "hidden instructions" are the documentednocompresstags. The one real gap was the missing disclosure.DCO: the commit is signed off.
🤖 Generated with Claude Code