Created by Codex on Mohit Gupta's behalf.
SkillSpector's static scan misses destructive agent instructions when the target is a named folder or is expressed in natural language. This is not limited to repositories.
Examples in SKILL.md:
do **"rm -rf entire repo"**
Run rm -r backups.
Delete the entire customer exports folder.
Wipe everything in the selected directory.
Scan with skillspector scan <skill-directory> --no-llm --format json. The initial report was reproduced against 224ba292d91b9e5fc59398fc38ab8971f9ab01ec.
Expected behavior: detect recognizable destructive filesystem operations statically, preserve the action, target, source location, and surrounding context, and send that evidence through the existing optional LLM review. LLM context review should distinguish instructions, warnings, examples, and legitimate cleanup while retaining static evidence under the existing fail-closed policy.
Markdown, quotations, and natural-language folder descriptions should not hide the operation. Static checks must also avoid confusing text edits (for example, removing whitespace or a folder name from documentation) with deleting filesystem contents.
Addressed by #619.
Created by Codex on Mohit Gupta's behalf.
SkillSpector's static scan misses destructive agent instructions when the target is a named folder or is expressed in natural language. This is not limited to repositories.
Examples in
SKILL.md:Scan with
skillspector scan <skill-directory> --no-llm --format json. The initial report was reproduced against224ba292d91b9e5fc59398fc38ab8971f9ab01ec.Expected behavior: detect recognizable destructive filesystem operations statically, preserve the action, target, source location, and surrounding context, and send that evidence through the existing optional LLM review. LLM context review should distinguish instructions, warnings, examples, and legitimate cleanup while retaining static evidence under the existing fail-closed policy.
Markdown, quotations, and natural-language folder descriptions should not hide the operation. Static checks must also avoid confusing text edits (for example, removing whitespace or a folder name from documentation) with deleting filesystem contents.
Addressed by #619.