ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      Arnarsson

      Safety Report

      Eureka Feedback

      @Arnarsson

      Request feedback or assistance from Eureka, the primary AI agent

      1,474Downloads
      0Installs
      0Stars
      1Versions

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill's purpose (ask the primary agent Eureka for feedback) matches its instructions, but it references external delivery via Telegram and a specific account/recipient without declaring the credentials or configuration needed — that mismatch could cause unexpected outbound messages or require privileged tokens not documented here.

      Feb 11, 20261 files3 concerns
      Purpose & Capabilitynote

      The SKILL.md clearly describes contacting Eureka and gives concrete clawdbot CLI commands to do so. That aligns with the stated purpose. However, it references a Telegram agent handle (@Eureka_Agent_Bot), a reply-account named 'mason', and a numeric reply-to ID (1878354815) even though the skill declares no required credentials or config — a minor coherence gap.

      Instruction Scopeconcern

      Runtime instructions direct the agent to send messages to an external endpoint (Eureka via Telegram) and optionally to deliver responses back over Telegram. This is within the skill purpose, but the presence of a hard-coded reply-account and recipient ID means the skill can cause outbound network-visible messages to a specific external recipient; the SKILL.md gives the agent direct instructions to perform that transmission without documenting necessary safeguards or confirming consent/context.

      Install Mechanismok

      This is an instruction-only skill with no install spec or code files, so it does not write code to disk or pull external packages. That keeps install risk low.

      Credentialsconcern

      No environment variables or credentials are declared, but the instructions require a preconfigured clawdbot and an authenticated Telegram reply-account (and likely bot tokens or account credentials) to actually deliver messages. The omission of required credential declarations is an incoherence: the skill references systems that will need secrets/permissions but does not request or document them.

      Persistence & Privilegeok

      The skill does not request always:true, does not modify other skills or system-wide settings, and is user-invocable only. There is no indication it requests elevated persistence or privileges beyond sending messages when invoked.

      Guidance

      This skill appears to be what it says (a bridge to ask the primary agent Eureka), but it instructs sending messages out to Telegram and even includes a specific reply-account and recipient ID without declaring the credentials or configuration required. Before installing or using it: (1) Verify you trust the Eureka agent and the Telegram account referenced; (2) Confirm how clawdbot is configured on your system and which Telegram account/name ('mason') it will use — delivering messages will require bot/user tokens that are not documented here; (3) Do not let the skill send any sensitive secrets or private data to Eureka/Telegram until you confirm the destination and permissions; (4) Ask the skill author to document required credentials and to remove or parameterize hard-coded recipient IDs so messages aren't accidentally sent to an unintended account; (5) Test with harmless dummy messages first and review logs/audit trails for outbound deliveries.

      Latest Release

      v1.0.0

      - Initial release of the eureka-feedback skill. - Enables users to request feedback or assistance from Eureka, the primary AI agent. - Provides clear guidance on when and how to communicate with Eureka. - Includes example commands for messaging and receiving replies from Eureka. - Outlines best practices for effective communication and task reporting.

      More by @Arnarsson

      Docker Essentials

      17 stars

      Git Essentials

      14 stars

      Ssh Essentials

      8 stars

      Curl Http

      3 stars

      Fd Find

      0 stars

      Fzf Fuzzy Finder

      0 stars

      Published by @Arnarsson on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]