CtrlK
BlogDocsLog inGet started
Tessl Logo

code-as-harness

证据确认重复摩擦后修 harness。Use: 历史重复已确认。Not: 未确认重复、首次 bug、review 反馈。Output: 未确认不强制 block;需 operator 决策发 interactive,否则行动后发 card(均含根因、证据、处置)。

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./cat-cafe-skills/code-as-harness/SKILL.md
SKILL.md
Quality
Evals
Security
Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

该 skill 的运行流程只在“猫侧摩擦上报/复现坐标”场景下处理 invocation 内的用户消息,并通过基于线索的证据检索(search_evidence/grep thread history)确认“重复”后再进入诊断,但没有任何步骤显示会自动读取/监控第三方作者的任意外部自由文本源(如邮箱/社工/推文流/GitHub/Jira/任意网页)本身。

Report incorrect finding
Repository
zts212653/clowder-ai
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.