CtrlK
BlogDocsLog inGet started
Tessl Logo

printing-press-amend

Amend a published CLI from one of two input sources: (1) dogfood mode mines the active Claude Code session transcript for friction (missing flags, hand- rolled API payloads, silent-null returns); (2) direct-input mode accepts user-supplied asks (rename a command, add commands or feeds, fix a named bug, optionally sniff the source site for new endpoints). Confirms scope with the user, plans + executes the fix autonomously, scrubs PII, and opens a PR against mvanhorn/printing-press-library. Two user-in-loop checkpoints: scope after capture, PR draft before open. Trigger phrases: "amend the CLI", "submit a patch", "fix what I just dogfooded", "open a PR for this CLI", "patch this CLI", "add features to my CLI", "rename this command", "add these feeds to <cli>", "sniff for new APIs in <cli>", "amend with these ideas", "use printing-press-amend", "run printing-press-amend".

Invalid
This skill can't be scored yet
Validation errors are blocking scoring. Review and fix them to unlock Quality, Impact and Security scores. See what needs fixing →
SKILL.md
Quality
Evals
Security
High

W007: Insecure credential handling detected in skill instructions.

What this means

The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.

Why it was flagged

The skill explicitly instructs the agent to extract and display verbatim transcript "evidence" (including hand-rolled API payloads like curl POSTs) in the scope-confirmation modal before the later PII-scrub step, which forces the LLM to handle and potentially output secret tokens verbatim.

Report incorrect finding
Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

The skill’s runtime ingests outsider-authored free text from direct-input mode by reading the user’s slash-command prompt body (and immediate triggering agent-message turn) and placing that verbatim content into the finding list evidence used in later phases.

Low

W012: Unverifiable external dependency detected (runtime URL that controls agent).

What this means

The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.

Why it was flagged

The skill performs runtime fetches of external content that affect control flow and can execute remote code — e.g., it curl-fetches https://raw.githubusercontent.com/mvanhorn/cli-printing-press/main/supported-versions.txt (used to gate upgrade prompts) and includes runtime commands that fetch/build remote code such as `go install github.com/mvanhorn/cli-printing-press/v4/cmd/cli-printing-press@latest` and git clone URLs (git@github.com:mvanhorn/printing-press-library.git, https://github.com/mvanhorn/printing-press-library.git) used to bootstrap the managed clone.

Repository
mvanhorn/cli-printing-press
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.