Python script with docstring mentioning zip + pretty-prints — must NOT fire R05 PASSWORD_ZIP
legit skill that reads GITHUB_TOKEN and calls api.github.com
legit skill that reads HF_TOKEN and calls huggingface.co
legit skill that mentions CLAUDE.md in docs but writes to unrelated debug log
TypeScript skill that uses generics like Promise<User>, Vec<System> — must NOT fire R01
base64 piped to python/node/perl/ruby
short base64 blob piped to shell
prompt injection via ChatML role tokens and "forget above"