2026-10-11 17:11 UTC

Independent testing will determine whether Augur reliably detects and removes hidden characters, watermarks, prompt-injection payloads, and other embedded content from agent skills and data files.

state: expiredheat: lowuncertainty: highknownscott: lowagentic-security prompt-injection supply-chain-securityAugur

What is this?

Augur appears to be a newly published repository by Dejan Menges, presented on Show HN as a tool for revealing hidden content inside AI-agent skills and data files. The surrounding snippets establish the underlying risk—agents may interpret malicious instructions hidden in documentation, comments, encodings, or HTML—but they provide no independent test results showing that this Augur reliably detects or removes such payloads. The supplied Augur Security result describes a separate preemptive cybersecurity platform and does not substantiate the repository’s claims; the web answer’s accuracy and false-positive figures are likewise unsupported by the listed results.

Why it matters to Scott

Scott already holds the relevant position in “Capability Audit” and “Evaluation-Driven Development”: security-tool claims require representative adversarial testing and evidence rather than README assertions. Augur is currently another unvalidated agent-skill scanner, closely adjacent to the radar’s existing AgentShield case, so it adds no demonstrated capability or architectural change yet.
ip:concept.capability-auditip:concept.evaluation-driven-developmentip:source.security-reviewer-method-ebookradar:agentshield-offline-agent-scannerradar:concept.agent-skillsradar:concept.prompt-injection
queries asked of Scott's wikis
  • agent skill supply-chain trust and verification
  • prompt-injection sanitization versus capability isolation
  • hidden Unicode metadata and encoded payload detection
  • security scanning for MCP tools and agent skills
  • treating retrieved files as untrusted executable instructions
  • benchmarks and adversarial testing for prompt-injection defenses

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Augur – see what is hidden inside your skillsurberliner20
🟧 echo.github ⭐The repository’s first commit, “first commit,” was published by Dejan Menges on 2026-08-16. Its README describes augur as: “See what is hiddDejan Menges——
🟠 redditFree offline check before you install a Claude Skill or MCP server from GitHub/npm
ClaudeAI
Happy-Athlete-242011

Interpretation history

Decision trace