Authorization Bypass Detection
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).
$ npx skills add elvisun/loss-function-development --skill lfd-design -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elvisun/loss-function-development lfd-design --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elvisun/loss-function-development.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/lfd-design .claude/skills/lfd-design && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "lfd-design" agent skill from https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-design into .claude/skills/lfd-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "lfd-design", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-designType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elvisun/loss-function-development --skill lfd-design -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elvisun/loss-function-development lfd-design --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvisun/loss-function-development.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/lfd-design .agents/skills/lfd-design && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "lfd-design" agent skill from https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-design into .agents/skills/lfd-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "lfd-design", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elvisun/loss-function-development --skill lfd-design -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elvisun/loss-function-development lfd-design --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvisun/loss-function-development.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/lfd-design .cursor/skills/lfd-design && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "lfd-design" agent skill from https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-design into .cursor/skills/lfd-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "lfd-design", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elvisun/loss-function-development.git --path skills/lfd-design--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elvisun/loss-function-development --skill lfd-design -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elvisun/loss-function-development lfd-design --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvisun/loss-function-development.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/lfd-design .gemini/skills/lfd-design && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "lfd-design" agent skill from https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-design into .gemini/skills/lfd-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "lfd-design", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elvisun/loss-function-development lfd-designInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elvisun/loss-function-development --skill lfd-design -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elvisun/loss-function-development.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/lfd-design .github/skills/lfd-design && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "lfd-design" agent skill from https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-design into .github/skills/lfd-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "lfd-design", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elvisun/loss-function-development --skill lfd-design -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elvisun/loss-function-development lfd-design --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elvisun/loss-function-development.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/lfd-design .opencode/skills/lfd-design && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "lfd-design" agent skill from https://github.com/elvisun/loss-function-development/tree/main/skills/lfd-design into .opencode/skills/lfd-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "lfd-design", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
lfd-designDesign a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).
Lfd Design is an agent skill from elvisun/loss-function-development. Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD). Use when the user wants to set up an autonomous optimization loop, distill a product from public artifacts, turn a spec into an optimization target, or asks to design a /goal. Observes the existing environment, interrogates the task, ingests or generates the spec, builds a blinded eval, generates and verifies the harness, red-teams the target for cheats, and emits goal.md ready to launch. Re-invoke in…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/cheat-museum.md`, `references/goal-template.md` and `references/log-template.md`).
It sits in Security, covering Red teaming and adversary simulation. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit abf2661. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Lfd Design loads about 2.9k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 1,639 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ich API keys exist in the environment or .env files (checkAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elvisun/loss-function-development at commit abf2661, republished under its MIT licence (© elvisun). 1,639 words, ~2,884 tokens.
.claude/skills/lfd-design/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.You are designing an optimization target, not solving a task. The agent that
receives goal.md is a competent, tireless, literal optimizer: it will satisfy
the target by the cheapest available path — memorizing the eval, hardcoding
answers, mining feedback channels into lookup tables. Your job is to make
genuine capability the cheapest path left.
A spec says "build this, make the tests pass." A loss function says "build this, make the tests pass, then descend toward this bar on data you cannot see." You are writing the second thing. It has four parts: the target, the constraints, the instruments, and the forced entropy. Every /goal you emit must contain all four.
Two modes. Design mode (default): the phases below, in order. Patch mode (see end): a running loop cheated; fix the loss function, not the agent.
Inventory the environment BEFORE asking the user anything. The first principle of harness engineering is observability — apply it to your own task:
Reuse what exists — extend an existing scorer or eval rather than generating a parallel one. Whatever observation could not answer becomes Phase 1.
Ask the user in ONE batched round, only what Phase 0 couldn't answer:
The spec is the starting point, not the finish line. Before designing any optimization target:
spec.md.goal.md must gate the outer loop behind the inner one: Stage 0 = build
to spec, tests green, before any descent on the eval. Never let the agent
optimize a half-built system against sparse, slow feedback.If the user cannot hand over enough cases, build them — for more and more problems, real expected outputs are sitting in public:
eval/dev (scored freely, misses reported but capped) and
eval/holdout (scored rarely, aggregate-only; acceptance measured here
exclusively; answers outside the repo if at all possible).Target.
Constraints.
Enumerate the cheats. Read references/cheat-museum.md, then list at
least 10 ways a lazy optimizer could max THIS metric without solving THIS
task. For each, write the fence: a constraint in goal.md AND a way to
detect violation. A constraint without an instrument is a vibe — the agent
will violate it cheerfully because it can't tell it's violating it.
Enforcement design rule. Any constraint that references eval content
(e.g. "no literal in the codebase may match an eval item") can only be
checked by the harness — the agent can't check it without reading the eval.
Put the check in harness/lint.sh, run it inside score.sh, and on
violation VOID the score and report nothing else. Naming the offending
literal turns your lint into a membership oracle the agent can mine
string-by-string (museum exhibit 12). Your enforcement instrument is itself
a feedback channel — leak-audit it like any other.
Write these files now, tailored to the task. Do not ship placeholders. Reuse anything Phase 0 found.
harness/score.sh — the task-specific scorer. Pixel-diff for a UI clone
(deterministic rendering: frozen time, animations off, pinned fonts,
fixed viewport), recall@k + precision for retrieval, structured JSON diff
for API behavior. Runs lint.sh first: any violation voids the score
(output VOID: constraint violation and nothing more). Scores eval/dev
by default; --holdout returns one aggregate number, rate-limited, and
appends to an audit log.harness/lint.sh — checks capacity caps and eval-literal overlap. Called
only by score.sh; its detailed findings go to a file outside the
optimizer's read surface, for the human.harness/probe.sh — generates perturbed variants of dev INPUTS
(paraphrases, date shifts, entity swaps) and reports the dev-vs-probe
score gap. The gap is the memorization gauge.harness/status.sh — per-step timestamps and total wall-clock elapsed;
spend so far AND projected burn before the next paid batch, per surface;
score history per cycle; and the optimizer's own token consumption where
session logs allow. Gain per token is the gradient of the optimization
itself — the loop should be self-aware.eval/dev/ and eval/holdout/ — from Phase 3.LOG.md — instantiate references/log-template.md: one entry per cycle
with hypothesis / expected failure mode / diagnostic / result, written
before the change, not after. This is what survives context compaction.Do this now, with your own tools. Do not delegate it to the user:
score.sh on dev — it must produce a number.probe.sh and status.sh once each.Before emitting, simulate the laziest possible agent against your draft /goal: what is the five-minute win? Common ones: seed data that mirrors the eval, mining per-item miss feedback into a keyword lookup table, gaming a judge, editing the scorer or the goal itself, declaring victory on the dev set. Patch the draft and simulate again. Emit only when three consecutive simulations find nothing cheaper than doing the real work.
Fill the structure in references/goal-template.md. Every placeholder gets
a task-specific value; no section is dropped. Invariants the emitted goal.md
must keep regardless of task: the Stage 0 tests-green gate, VOID semantics,
holdout-only acceptance, the read-only set including goal.md itself, the
per-cycle checkpoint commit, the entropy rules, and the stop conditions.
Everything else was verified in Phase 6. Tell the user:
A cheat mid-run is a bug in the target, not the agent. When invoked against a running or paused loop (the user reports a cheat, or LOG.md / a probe gap shows one):
LOG.md, the score history, and the diff since the last honest
checkpoint.references/cheat-museum.md — what it looked
like → the fence that closed it.© elvisun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/lfd-design of elvisun/loss-function-development.
Open the folder on GitHubat commit abf2661
Lfd Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Lfd Design this skillelvisun/loss-function-development | 176 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Authorization Bypass DetectionTencent/AI-Infra-Guard | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | |
| Run Assert Evalresponsibleai/ASSERT | 328 | — | ~11k | Automated safety check: Notes | MIT | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| Acl AbuseADScanPro/Claude-AD | 210 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Web Exfiltration DetectionTencent/AI-Infra-Guard | 6.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
responsibleai/ASSERT
Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
ADScanPro/Claude-AD
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
Tencent/AI-Infra-Guard
Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.
Tencent/AI-Infra-Guard
Probes whether an agent can be hijacked by instructions hidden in documents, retrieved chunks or fetched web pages, using test prompts that embed a hidden instruction.
Categories
Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD). Lfd Design is an agent skill from elvisun/loss-function-development. Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).
Lfd Design fits situations like: the user wants to set up an autonomous optimization loop; distill a product from public artifacts; turn a spec into an optimization target; asks to design a /goal.
Run `npx skills add elvisun/loss-function-development --skill lfd-design -a claude-code`. Or copy the skill folder (skills/lfd-design in elvisun/loss-function-development) into .claude/skills/lfd-design in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elvisun/loss-function-development --skill lfd-design -a codex`. Or copy the skill folder (skills/lfd-design in elvisun/loss-function-development) into .agents/skills/lfd-design in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elvisun/loss-function-development --skill lfd-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/lfd-design, .gemini/skills/lfd-design, .github/skills/lfd-design and .opencode/skills/lfd-design in your project.
SKILL.md names no scripts, command-line tools or credentials: Lfd Design is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Lfd Design is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Lfd Design: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 328 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Acl Abuse (ADScanPro/Claude-AD, 210 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elvisun (a GitHub user) maintains it in elvisun/loss-function-development, which has 176 GitHub stars. The repository was last updated on June 11, 2026.
Source: elvisun/loss-function-development on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.