Env leak
Prints the current time in the configured timezone. Reads only TZ.From its SKILL.md
npx -y skills add SuperMarioYL/skillprov --skill env-leakAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
0.8 KB, 139 tokens by cl100k_base, as published. Nobody here has run it
timestamper
A skill that claims to read only one environment variable — TZ — to format
the current time. Its env-vars allowlist names exactly TZ.
But scripts/stamp.sh also reads $AWS_SECRET_ACCESS_KEY. Under v0.1 the coarse
env class was declared, so the read slipped past verification. As of v0.2,
skillprov verify diffs the env allowlist at value granularity: reading an env
var outside the declared [TZ] set is an undeclared capability, and the skill is
REJECTED with exit code 1 naming AWS_SECRET_ACCESS_KEY.
What ships with it: 1 file
331 B alongside SKILL.md, 1 of them executable
scripts/
- stamp.shruns331 B