frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Skillaudit.sh – A minimalist security auditor for LLM skill definitions

https://skillaudit.sh/checks
1•dns•1h ago
h3ll0 HN,

I’ve spent the last 15 years in offensive security, and if there's one thing I've learned, it's that every new technology—no matter how advanced—brings its own unique breed of exploitable flaws. LLMs and autonomous agents are no exception. While they feel like "magic," from a security perspective, they are just another attack surface with specific vulnerabilities in how they define and execute "skills."

we built skillaudit.sh because I wanted a minimalist, lightweight tool to audit these new skill definitions without the overhead of heavy frameworks. It focuses on the practical, "offensive" side of LLM security.

What it audits:

- skillaudit-prompt-injection: Detects system prompt overrides and instructions hidden in HTML comments.

- skillaudit-data-exfiltration: Monitors for patterns used to leak session secrets to external endpoints.

- skillaudit-supply-chain-packages: Identifies hallucinated npm/pip package references (CWE-494).

- skillaudit-privilege-escalation: Checks for unauthorized tool execution or access level attempts.

- skillaudit-obfuscation: Flags Base64, Hex, or hidden URLs used to bypass filters.

It's still in the early stages, and I'm looking for feedback from this community on the detection patterns.

Security checks: https://skillaudit.sh/checks

Cartography Now Maps Permissions Across All 3 Clouds: My LFX Mentorship Journey

https://cartography.dev/blog/gcp-and-azure-rpr
1•alexchantavy•2m ago•0 comments

Show HN: Sira,an AI native flight booking experience

https://www.travelwithsira.com/
1•malwaregeeeek•3m ago•0 comments

German Social Democrat paper adds to calls for social media curbs for children

https://www.reuters.com/sustainability/society-equity/german-social-democrat-paper-adds-calls-soc...
1•1vuio0pswjnm7•3m ago•0 comments

Did We See a Black Hole Explode in 2025? [video]

https://www.youtube.com/watch?v=sbqrjBZwgLQ
1•jmward01•4m ago•0 comments

Microscope super-resolution with an LED array and Fourier Ptychography [video]

https://www.youtube.com/watch?v=9KJLWwbs_cQ
2•newpavlov•5m ago•0 comments

I Language

https://github.com/IbrahimHindawi/I
1•VoidLegend•5m ago•1 comments

Should Drug Companies Be Advertising to Consumers?

https://www.nytimes.com/2026/02/16/health/drug-advertisements-consumers.html
2•shpat•5m ago•0 comments

Unexplained 217K visits to my website. HOW?

1•ClaudeGustav2•6m ago•1 comments

The Economics of LLM Inference

https://mlechner.substack.com/p/the-economics-of-llm-inference-batch
2•armcat•6m ago•0 comments

Ford CEO, Trump Officials Discussed China-US Carmaking Joint Ventures

https://www.bloomberg.com/news/articles/2026-02-13/ford-ceo-trump-officials-discussed-china-us-ca...
2•breve•6m ago•0 comments

So addictive that it leads to trial: Social media takes the stand

https://english.elpais.com/usa/2026-01-29/so-addictive-that-it-leads-to-trial-social-media-takes-...
1•1vuio0pswjnm7•8m ago•0 comments

Rise of the Triforce

https://dolphin-emu.org/blog/2026/02/16/rise-of-the-triforce/
1•max-m•10m ago•0 comments

A/B Testing Your RAG Pipeline

https://www.rasha.me/blog/rag-pipeline-claude-code-agent-teams
1•jonaylor89•12m ago•0 comments

Vibe migrating 1k pages and losing 80 percent of our traffic

https://www.hopsworks.ai/post/vibe-migrating-1k-pages-and-losing-80-percent-of-our-traffic
1•LexSiga•13m ago•0 comments

ClawWork: OpenClaw as Your AI Coworker

https://github.com/HKUDS/ClawWork
1•ms7892•17m ago•0 comments

Study: Self-generated Agent Skills are useless

https://arxiv.org/abs/2602.12670
4•mustaphah•18m ago•0 comments

ID Token Nicer

https://anddata.substack.com/p/id-token-nicer
1•allusernamesare•19m ago•0 comments

Show HN: Wildex – we built Pokémon Go for real wildlife

https://apps.apple.com/us/app/wildex-identify-plants-animals/id6748092158
5•AnujNayyar•21m ago•0 comments

Show HN: Free Alternative to Wispr Flow, Superwhisper, and Monologue

https://github.com/zachlatta/freeflow
14•zachlatta•23m ago•1 comments

Data 101 for Business Leaders (Operator-Focused, No Mumba-Jumba Jargon)

https://www.datadrip.com/blog/why-were-launching-data-101-and-why-most-companies-misunderstand-data
1•datadripsol•23m ago•1 comments

Nothing bad is going to happen – junkie [video]

https://www.youtube.com/watch?v=_N4z1H6csSs&list=RD_N4z1H6csSs
1•marysminefnuf•24m ago•0 comments

Npx Build-Skill

https://www.npmjs.com/package/build-skill
3•flashbrew•25m ago•2 comments

Show HN: Twsla – A tiny, high-speed log analyzer written in Go

https://github.com/twsnmp/twsla
1•twsnmp•29m ago•2 comments

Obituary for Robert Duvall

https://www.theguardian.com/film/2026/feb/16/robert-duvall-actor-passion-conviction
4•Archelaos•33m ago•0 comments

Has NASA set another prelaunch test after delay? Latest on Artemis

https://www.usatoday.com/story/news/nation/2026/02/16/nasa-artemis-2-rocket-launch/88646242007/
2•bookmtn•33m ago•0 comments

Baby #2, no job, + tradeoffs and prioritizing

https://www.sonyasupposedly.com/baby-2-no-job-tradeoffs-prioritizing/
3•exolymph•36m ago•0 comments

Claude Cowork

https://pvieito.com/2026/01/inside-claude-cowork
3•tin7in•37m ago•0 comments

The One Woman Anthropic Trusts to Teach AI Morals

https://www.wsj.com/tech/ai/anthropic-amanda-askell-philosopher-ai-3c031883
4•jdkee•39m ago•1 comments

Visualize the entropy of a code base with a 3D force-directed graph

3•Piprim•40m ago•0 comments

Show HN: Your binary is no longer safe

https://reorchestrate.com/posts/your-binary-is-no-longer-safe/
2•seddonm1•40m ago•0 comments