ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      stevengonsalvez

      Safety Report

      Reflect

      @stevengonsalvez

      Self-improvement through conversation analysis. Extracts learnings from corrections and success patterns, proposes updates to agent files or creates new skil...

      6,271Downloads
      48Installs
      13Stars
      2Versions
      File Management2,100Web Scraping958Education & Learning489

      Security Analysis

      medium confidence
      Suspicious0.08 risk

      The skill's files and runtime instructions largely match a 'reflection' capability, but it has several high-impact behaviors (editing global agent files, committing changes, installing hooks, and shipping conversation logs) that merit careful review before installing.

      Feb 17, 202619 files4 concerns
      Purpose & Capabilitynote

      Name/description match the included scripts and docs: detecting signals, proposing edits, creating new skills, and updating agent files. However, the skill declares no env/credentials while expecting to read and modify ~/.claude agents, create files under ~/.claude/.skills and run git — a high-privilege scope that is functionally justified by the purpose but broader than many users may expect.

      Instruction Scopeconcern

      SKILL.md and scripts explicitly instruct reading transcripts, scanning logs, writing learnings, creating skills under .claude/skills, and running git add/commit via Edit/Bash tools. That behavior is consistent with the stated goal but grants the skill permission to permanently change many user/global agent files and state. The skill also provides hook installation that can trigger auto-reflect on context compaction — potentially altering behavior across sessions.

      Install Mechanismok

      No external install spec or remote downloads are used; this is an instruction-plus-local-scripts package. Scripts list a Python dependency (pyyaml) but there is no automated installer that fetches arbitrary remote code. This lowers some install risk, though the shipped scripts will execute locally.

      Credentialsnote

      The skill requests no environment variables or credentials, which is appropriate. However it expects access to user files and directories (e.g., ~/.claude/, ~/.reflect/, .claude/skills/) and to run shell commands. Those accesses are necessary to implement its purpose but are high-privilege and should be explicitly accepted by the user.

      Persistence & Privilegeconcern

      always:false (good), but the skill is designed to make permanent edits to global agent files, create skills, and commit them to git. It also includes optional hooks that can run on PreCompact events and an 'auto-reflect' mode that can be enabled. These capabilities give it long-term, cross-session impact, so enablement and human approval processes should be reviewed before allowing it to run with write/edit privileges.

      Guidance

      This skill can read session transcripts and permanently edit your agent files (e.g., ~/.claude/agents, .claude/skills) and commit changes. Before installing, do the following: (1) Inspect the included scripts (signal_detector.py, output_generator.py, state_manager.py, precompact_reflect.py) to confirm they do only what you expect. (2) Check scripts/logs/chat.json — it appears a conversation log is packaged; ensure it contains no sensitive data. (3) Back up ~/.claude and any agent files you care about. (4) Don't enable auto-reflect or install hooks until you trust the code; prefer manual /reflect reviews first. (5) Run the scripts in a sandbox or with reduced permissions to observe behavior. (6) If you allow commits, verify it will not push to remote repos or leak data externally. If you want, I can highlight specific lines in the scripts that implement file writes, git commits, or reading of transcript/log files for a more detailed audit.

      Latest Release

      v2.1.0

      Add Security category to signal detection, fix agent_mappings.md root-level agents, add Memory integration guidance, consistency fixes across reference files

      More by @stevengonsalvez

      Bitwarden

      0 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Published by @stevengonsalvez on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]