Independent testing will determine whether Augur reliably detects and removes hidden characters, watermarks, prompt-injection payloads, and other embedded content from agent skills and data files.
state: expiredheat: lowuncertainty: highknownscott: lowagentic-security prompt-injection supply-chain-securityAugur
What is this?
Augur appears to be a newly published repository by Dejan Menges, presented on Show HN as a tool for revealing hidden content inside AI-agent skills and data files. The surrounding snippets establish the underlying risk—agents may interpret malicious instructions hidden in documentation, comments, encodings, or HTML—but they provide no independent test results showing that this Augur reliably detects or removes such payloads. The supplied Augur Security result describes a separate preemptive cybersecurity platform and does not substantiate the repository’s claims; the web answer’s accuracy and false-positive figures are likewise unsupported by the listed results.
Why it matters to Scott
Scott already holds the relevant position in “Capability Audit” and “Evaluation-Driven Development”: security-tool claims require representative adversarial testing and evidence rather than README assertions. Augur is currently another unvalidated agent-skill scanner, closely adjacent to the radar’s existing AgentShield case, so it adds no demonstrated capability or architectural change yet.
ip:concept.capability-auditip:concept.evaluation-driven-developmentip:source.security-reviewer-method-ebookradar:agentshield-offline-agent-scannerradar:concept.agent-skillsradar:concept.prompt-injection
queries asked of Scott's wikis
- agent skill supply-chain trust and verification
- prompt-injection sanitization versus capability isolation
- hidden Unicode metadata and encoded payload detection
- security scanning for MCP tools and agent skills
- treating retrieved files as untrusted executable instructions
- benchmarks and adversarial testing for prompt-injection defenses
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (3) — ⭐ canonical anchor
Interpretation history
2026-08-20T21:29:01Z
The broader scanner category remains plausible, but Augur has attracted no independent testing, adoption, or substantive discussion; adjacent scanner activity does not validate its claims. Its launch window has faded, so retire the case unless concrete adversarial results emerge.
2026-08-18T20:38:50Z
A separate offline skill/MCP scanner corroborates demand for pre-installation scanning, but it neither tests Augur nor validates Augur’s detection and cleaning claims. The case remains an unvalidated repository-specific capability claim despite stronger evidence for the broader tool category.
2026-08-18T20:23:31Z
evidence attached: reddit.post.1vs02pa — This independently corroborates the emerging need for offline scanning of skills and MCP packages for hidden characters and prompt-injection payloads.
2026-08-17T17:43:02Z
No independent testing, implementation uptake, or discussion has appeared; the case remains an unvalidated repository claim and has cooled after launch.
2026-08-17T17:34:56Z
grounded: known/low — Scott already holds the relevant position in “Capability Audit” and “Evaluation-Driven Development”: security-tool claims require representative adversarial tes
2026-08-17T17:32:35Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49334301 -> echo.github.db9e43cbe7 by Dejan Menges
2026-08-17T17:31:29Z
case created — The released scanner is a usable security artifact addressing hidden-content attacks against agents consuming untrusted files and skills.
Decision trace
- 08-21 07:29expireThe broader scanner category remains plausible, but Augur has attracted no independent testing, adoption, or substantive discussion; adjacent scanner activity does not validate its claims. Its launch
- 08-21 07:29alert_silentThe only delta is staleness and negligible engagement movement, with no new evidence about Augur’s reliability or uptake; there is nothing decision-relevant to surface.
- 08-21 07:29alert_routeThe only delta is staleness and negligible engagement movement, with no new evidence about Augur’s reliability or uptake; there is nothing decision-relevant to surface.
- 08-19 06:38repriceA separate offline skill/MCP scanner corroborates demand for pre-installation scanning, but it neither tests Augur nor validates Augur’s detection and cleaning claims. The case remains an unvalidated
- 08-19 06:38alert_silentThe new evidence is an adjacent developer’s self-reported implementation and small fixture test, not independent adversarial testing or adoption of Augur. It adds ecosystem context but no decision-rel
- 08-19 06:38alert_routeThe new evidence is an adjacent developer’s self-reported implementation and small fixture test, not independent adversarial testing or adoption of Augur. It adds ecosystem context but no decision-rel
- 08-19 06:24alert_silentThis is a separate scanner’s self-reported result on six malicious fixtures plus 32 benign bundles, not independent testing of Augur. The claimed non-executing package retrieval and graded evaluation
- 08-19 06:24surface_candidateThis is a separate scanner’s self-reported result on six malicious fixtures plus 32 benign bundles, not independent testing of Augur. The claimed non-executing package retrieval and graded evaluation
- 08-19 06:24alert_routeThis is a separate scanner’s self-reported result on six malicious fixtures plus 32 benign bundles, not independent testing of Augur. The claimed non-executing package retrieval and graded evaluation
- 08-19 06:23attachThis independently corroborates the emerging need for offline scanning of skills and MCP packages for hidden characters and prompt-injection payloads.
- 08-19 06:22propose_attachThis independently corroborates the emerging need for offline scanning of skills and MCP packages for hidden characters and prompt-injection payloads.
- 08-18 03:43repriceNo independent testing, implementation uptake, or discussion has appeared; the case remains an unvalidated repository claim and has cooled after launch.
- 08-18 03:43alert_silentThe reobservation adds no consequential evidence beyond the already-known release, so this can wait for independent adversarial results or meaningful adoption.
- 08-18 03:43alert_routeThe reobservation adds no consequential evidence beyond the already-known release, so this can wait for independent adversarial results or meaningful adoption.
- 08-18 03:38alert_silentAugur is a newly published open-source scanner, but the evidence only establishes its availability and README-described feature set. It provides no representative adversarial results, demonstrated det
- 08-18 03:38alert_routeAugur is a newly published open-source scanner, but the evidence only establishes its availability and README-described feature set. It provides no representative adversarial results, demonstrated det
- 08-18 03:34groundScott already holds the relevant position in “Capability Audit” and “Evaluation-Driven Development”: security-tool claims require representative adversarial testing and evidence rather than README ass
- 08-18 03:32promote_anchororigin walk conf 0.98
- 08-18 03:31createThe released scanner is a usable security artifact addressing hidden-content attacks against agents consuming untrusted files and skills.