CtrlK
BlogDocsLog inGet started
Tessl Logo

twmd-founder-lens

Creator's-lens weekly pass — the first routine that deliberately leaves the skull. Renders + cold-reads the live product as a first-time reader, pulls one slice of off-repo signal, applies the meaning/taste gate no instrument can compute, and generates 哲宇-voice proposals routed to evolution-roadmap / OBSERVER-QUEUE / ARTICLE-INBOX. Honest about its same-DNA ceiling (#65f): it stages the external gaze but is never the external ruler, and never crosses the §Reserved four. TRIGGER when: user says "founder lens", "創造者透鏡", "哲宇的眼睛", "跑 founder-lens", or routine `twmd-founder-lens-weekly` fires.

Invalid
This skill can't be scored yet
Validation errors are blocking scoring. Review and fix them to unlock Quality, Impact and Security scores. See what needs fixing →
SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

[SKILL.md] 指定 Stage 1/2 會「Chrome MCP render 活站 + 冷讀文章」與「拉一片 off-repo 訊號(外部引用 / 社群 buzz / contributor batch)」並進一步要求「嚴格完整讀取並執行 …FOUNDER-LENS-PIPELINE.md 整份 SOP」,因此其 required runtime workflow會攝取外部/社群來源的使用者可投稿文字而構成間接提示注入風險。

Report incorrect finding
Repository
frank890417/taiwan-md
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.