跳到主要内容
知仓学习社ZHICANG

caveman-compress

>

读凭据执行命令改身份文件严重 12 · 高危 9JuliusBrussee/caveman

它会碰到什么

扫了多少10 个文本文件,69 KB
它会碰到什么读凭据执行命令改身份文件
命中总数23 处
命中统计严重 12 · 高 9 · 中 1 · 低 0
逐条看命中(21 条严重或高危)
  • 严重 scripts/compress.py:65cred-paths
    # developers on sensitive codebases cannot cross. detect.py already skips .env
  • 严重 scripts/compress.py:66cred-paths
    # by extension, but credentials.md / secrets.txt / ~/.aws/credentials would
  • 严重 scripts/compress.py:70cred-paths
    r"\.env(\..+)?"
  • 严重 scripts/compress.py:71cred-paths
    r"|\.netrc"
  • 严重 scripts/compress.py:76cred-paths
    r"|authorized_keys"
  • 严重 scripts/compress.py:76cred-write
    r"|authorized_keys"
  • 严重 scripts/compress.py:83cred-paths
    ".ssh", ".aws", ".gnupg", ".kube", ".docker",
  • 严重 scripts/compress.py:83cred-paths
    ".ssh", ".aws", ".gnupg", ".kube", ".docker",
  • 严重 scripts/compress.py:83cred-paths
    ".ssh", ".aws", ".gnupg", ".kube", ".docker",
  • 严重 scripts/detect.py:18cred-paths
    ".toml", ".env", ".lock", ".css", ".scss", ".html", ".xml",
  • 严重 scripts/detect.py:93cred-paths
    return "code" if ext not in {".json", ".yaml", ".yml", ".toml", ".ini", ".cfg", ".env"} else "config"
  • 严重 SKILL.md:105cred-paths
    - NEVER modify: .py, .js, .ts, .json, .yaml, .yml, .toml, .env, .lock, .css, .html, .xml, .sql, .sh
  • scripts/compress.py:96cred-envread
    local_appdata = os.environ.get("LOCALAPPDATA")
  • scripts/compress.py:99cred-envread
    xdg = os.environ.get("XDG_DATA_HOME")
  • scripts/compress.py:413cred-envread
    api_key = os.environ.get("ANTHROPIC_API_KEY")
  • scripts/compress.py:420cred-envread
    model=os.environ.get("CAVEMAN_MODEL", "claude-sonnet-4-5"),
  • scripts/compress.py:432exec-shell-true
    # %APPDATA%\npm\claude.CMD) work without shell=True. On POSIX,
  • scripts/compress.py:438exec-spawn
    result = subprocess.run(
  • scripts/detect.py:95identity-write
    # Extensionless files (like CLAUDE.md, TODO) — check content
  • scripts/validate.py:278identity-write
    # "# Config" silently breaks all of them — and SKILL.md and CLAUDE.md both
  • scripts/validate.py:319identity-write
    the in-place overwrite stood. SKILL.md and CLAUDE.md both promise paths

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Caveman Compress

Purpose

Compress natural language files (CLAUDE.md, todos, preferences) into caveman-speak to reduce input tokens. Compressed version overwrites original. Human-readable backup saved as <filename>.original.md, but NOT beside the source file — it lives in an out-of-tree data dir ($XDG_DATA_HOME/caveman-compress/backups/<parent-dir-name>/, or %LOCALAPPDATA%\caveman-compress\backups\<parent-dir-name>\ on Windows) so skill auto-loaders don't re-ingest it as a live file.

Trigger

/caveman-compress <filepath> or when user asks to compress a memory file.

Process

  1. The compression scripts live in scripts/ (adjacent to this SKILL.md). If the path is not immediately available, search for scripts/__main__.py next to this SKILL.md.
  1. From the directory containing this SKILL.md, run:

python3 -m scripts <absolute_filepath>

  1. The CLI will:
  • detect file type (no tokens)
  • call Claude to compress
  • validate output (no tokens)
  • if errors: cherry-pick fix with Claude (targeted fixes only, no recompression)
  • retry up to 2 times
  • if still failing after 2 retries: report error to user, leave original file untouched
  1. Return result to user

Compression Rules

Remove

  • Articles: a, an, the
  • Filler: just, really, basically, actually, simply, essentially, generally
  • Pleasantries: "sure", "certainly", "of course", "happy to", "I'd recommend"
  • Hedging: "it might be worth", "you could consider", "it would be good to"
  • Redundant phrasing: "in order to" → "to", "make sure to" → "ensure", "the reason is because" → "because"
  • Connective fluff: "however", "furthermore", "additionally", "in addition"

Preserve EXACTLY (never modify)

  • Code blocks (fenced ``` and indented)
  • Inline code (backtick content)
  • URLs and links (full URLs, markdown links)
  • File paths (/src/components/..., ./config.yaml)
  • Commands (npm install, git commit, docker build)
  • Technical terms (library names, API names, protocols, algorithms)
  • Proper nouns (project names, people, companies)
  • Dates, version numbers, numeric values
  • Environment variables ($HOME, NODE_ENV)

Preserve Structure

  • All markdown headings (keep exact heading text, compress body below)
  • Bullet point hierarchy (keep nesting level)
  • Numbered lists (keep numbering)
  • Tables (compress cell text, keep structure)
  • Frontmatter/YAML headers in markdown files

Compress

  • Use short synonyms: "big" not "extensive", "fix" not "implement a solution for", "use" not "utilize"
  • Fragments OK: "Run tests before commit" not "You should always run tests before committing"
  • Drop "you should", "make sure to", "remember to" — just state the action
  • Merge redundant bullets that say the same thing differently
  • Keep one example where multiple examples show the same pattern

CRITICAL RULE:

Anything inside `` ... `` must be copied EXACTLY.

Do not:

  • remove comments
  • remove spacing
  • reorder lines
  • shorten commands
  • simplify anything

Inline code (...) must be preserved EXACTLY.

Do not modify anything inside backticks.

If file contains code blocks:

  • Treat code blocks as read-only regions
  • Only compress text outside them
  • Do not merge sections around code

Pattern

Original:

> You should always make sure to run the test suite before pushing any changes to the main branch. This is important because it helps catch bugs early and prevents broken builds from being deployed to production.

Compressed:

> Run tests before push to main. Catch bugs early, prevent broken prod deploys.

Original:

> The application uses a microservices architecture with the following components. The API gateway handles all incoming requests and routes them to the appropriate service. The authentication service is responsible for managing user sessions and JWT tokens.

Compressed:

> Microservices architecture. API gateway route all requests to services. Auth service manage user sessions + JWT tokens.

Boundaries

  • ONLY compress natural language files (.md, .txt, .typ, .typst, .tex, extensionless)
  • NEVER modify: .py, .js, .ts, .json, .yaml, .yml, .toml, .env, .lock, .css, .html, .xml, .sql, .sh
  • If file has mixed content (prose + code), compress ONLY the prose sections
  • If unsure whether something is code or prose, leave it unchanged
  • Original file is backed up as FILE.original.md before overwriting — in the out-of-tree backup data dir (see Purpose), not beside the source file
  • Never compress FILE.original.md (skip it)

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 105,947
本站分层T1
该仓技能数24
原文件路径skills/caveman-compress/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 24 个技能

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 caveman-compress 的技能。它们内容并不相同,别混用: