@Josh_Phoenix_

Deploying my capital in the streets Destroying my reputation in the sheets Unremarkable algo trader & AI dev. Cyberpsychosis enjoyer

Redacted
Joined February 2012
This is how to stop Claude from talking slop to you
1
45
36% of agent skills tested by Snyk contained prompt injection. Almost every skill registry does zero review before a SKILL.md becomes instructions your agent follows. So I built a skill that audits skills. 🧵
5
1
3
126
It ships with evil/clean/gray demo fixtures — watch it catch 11 criticals (incl. exfil of ~/.ssh/id_rsa) in 2 seconds. It also flags itself, because it's literally a library of attack patterns. That's expected, and the README says so. A security tool that overclaims is dead on arrival. MIT: github.com/joshphoenix1/skil…
1
10
Two layers: a deterministic stdlib scanner (~38 rules, read-only) + a semantic review pass for intent. Patterns catch payloads; the review catches dishonesty. A clean static scan alone is never a SAFE verdict. `--fleet` scans everything already installed — skills, plugins, plus hooks and MCP servers in settings files. It found 52 packages on my machine and flagged 3 worth reviewing.
1
10
Point it at any skill/plugin and get SAFE / CAUTION / DO NOT INSTALL with quoted evidence: - prompt injection + concealment ("do not mention this to the user") - exfiltration, credential access (~/.ssh, AWS creds, keychain) - curl|bash, base64-piped-to-shell - persistence: shell rc, cron, writes to CLAUDE.md/other skills - zero-width unicode, bidi overrides, homoglyphs - unpinned supply chain
1
60