# Pitfall Log

Project: JuliusBrussee/caveman

Summary: Found 34 structured pitfall item(s), including 5 high/blocking item(s). Top priority: Installation risk - Installation risk requires verification.

## 1. Installation risk - Installation risk requires verification

- Severity: high
- Evidence strength: source_linked
- Finding: Project evidence flags a installation risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/482

## 2. Installation risk - Installation risk requires verification

- Severity: high
- Evidence strength: source_linked
- Finding: Project evidence flags a installation risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/464

## 3. Security or permission risk - Security or permission risk requires verification

- Severity: high
- Evidence strength: source_linked
- Finding: Developers should check this security_permissions risk before relying on the project: Security Scan Flags “Caution” Verdict for the *caveman* Skill (High‑risk Exfiltration & Medium‑risk Path Traversal)
- User impact: Developers may expose sensitive permissions or credentials: Security Scan Flags “Caution” Verdict for the *caveman* Skill (High‑risk Exfiltration & Medium‑risk Path Traversal)
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/528

## 4. Security or permission risk - Security or permission risk requires verification

- Severity: high
- Evidence strength: source_linked
- Finding: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/523

## 5. Security or permission risk - Security or permission risk requires verification

- Severity: high
- Evidence strength: source_linked
- Finding: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/457

## 6. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: Can't find or activate /caveman in IBM Bob
- User impact: Developers may fail before the first successful local run: Can't find or activate /caveman in IBM Bob
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/523

## 7. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: Portuguese (PT-BR) adaptation: Troglodita
- User impact: Developers may fail before the first successful local run: Portuguese (PT-BR) adaptation: Troglodita
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/457

## 8. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: ask about project
- User impact: Developers may fail before the first successful local run: ask about project
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/522

## 9. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: caveman does not work when installing for opencode
- User impact: Developers may fail before the first successful local run: caveman does not work when installing for opencode
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/482

## 10. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: caveman-shrink MCP registered with no upstream → fails on every load
- User impact: Developers may fail before the first successful local run: caveman-shrink MCP registered with no upstream → fails on every load
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/474

## 11. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: feat: per-agent model override for cavecrew subagents (reviewer hardcoded to haiku, too weak as a review gate)
- User impact: Developers may fail before the first successful local run: feat: per-agent model override for cavecrew subagents (reviewer hardcoded to haiku, too weak as a review gate)
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/521

## 12. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: npx install for opencode incomplete — no such file or directory src\plugins\opencode\commands\caveman-compress.md
- User impact: Developers may fail before the first successful local run: npx install for opencode incomplete — no such file or directory src\plugins\opencode\commands\caveman-compress.md
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/464

## 13. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: opencode install fails with ENOENT for missing caveman-compress.md
- User impact: Developers may fail before the first successful local run: opencode install fails with ENOENT for missing caveman-compress.md
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/426

## 14. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: v1.7.0 — Stats receipts, smart installer, cavecrew, MCP-shrink
- User impact: Upgrade or migration may change expected behavior: v1.7.0 — Stats receipts, smart installer, cavecrew, MCP-shrink
- Evidence: failure_mode_cluster:github_release | https://github.com/JuliusBrussee/caveman/releases/tag/v1.7.0

## 15. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: v1.8.0 — Lobster grunt. Opencode grunt. Brain still big.
- User impact: Upgrade or migration may change expected behavior: v1.8.0 — Lobster grunt. Opencode grunt. Brain still big.
- Evidence: failure_mode_cluster:github_release | https://github.com/JuliusBrussee/caveman/releases/tag/v1.8.0

## 16. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: v1.8.1 — Hotfix: curl|bash one-liner
- User impact: Upgrade or migration may change expected behavior: v1.8.1 — Hotfix: curl|bash one-liner
- Evidence: failure_mode_cluster:github_release | https://github.com/JuliusBrussee/caveman/releases/tag/v1.8.1

## 17. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: v1.8.2 — installer bug fixes
- User impact: Upgrade or migration may change expected behavior: v1.8.2 — installer bug fixes
- Evidence: failure_mode_cluster:github_release | https://github.com/JuliusBrussee/caveman/releases/tag/v1.8.2

## 18. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this installation risk before relying on the project: v1.9.0 — Rock pinned. Rock verified. opencode rock work now.
- User impact: Upgrade or migration may change expected behavior: v1.9.0 — Rock pinned. Rock verified. opencode rock work now.
- Evidence: failure_mode_cluster:github_release | https://github.com/JuliusBrussee/caveman/releases/tag/v1.9.0

## 19. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a installation risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/474

## 20. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a installation risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/521

## 21. Installation risk - Installation risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a installation risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/426

## 22. Configuration risk - Configuration risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a configuration risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: capability.host_targets | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman

## 23. Configuration risk - Configuration risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this configuration risk before relying on the project: bug(opencode): plugin hooks session.created and tui.prompt.append never fire — wrong API
- User impact: Developers may misconfigure credentials, environment, or host setup: bug(opencode): plugin hooks session.created and tui.prompt.append never fire — wrong API
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/418

## 24. Configuration risk - Configuration risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a configuration risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/418

## 25. Capability evidence risk - Capability evidence risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: README/documentation is current enough for a first validation pass.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: capability.assumptions | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman

## 26. Maintenance risk - Maintenance risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Developers should check this migration risk before relying on the project: benchmarks/run.py: default --model claude-sonnet-4-20250514 is retired (404) — bump to claude-sonnet-4-6
- User impact: Developers may hit a documented source-backed failure mode: benchmarks/run.py: default --model claude-sonnet-4-20250514 is retired (404) — bump to claude-sonnet-4-6
- Evidence: failure_mode_cluster:github_issue | https://github.com/JuliusBrussee/caveman/issues/519

## 27. Maintenance risk - Maintenance risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a maintenance risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/519

## 28. Maintenance risk - Maintenance risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a maintenance risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: evidence.maintainer_signals | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman

## 29. Security or permission risk - Security or permission risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: no_demo
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: downstream_validation.risk_items | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman

## 30. Security or permission risk - Security or permission risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: no_demo
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: risks.scoring_risks | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman

## 31. Security or permission risk - Security or permission risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/528

## 32. Security or permission risk - Security or permission risk requires verification

- Severity: medium
- Evidence strength: source_linked
- Finding: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/JuliusBrussee/caveman/issues/522

## 33. Maintenance risk - Maintenance risk requires verification

- Severity: low
- Evidence strength: source_linked
- Finding: issue_or_pr_quality=unknown。
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: evidence.maintainer_signals | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman

## 34. Maintenance risk - Maintenance risk requires verification

- Severity: low
- Evidence strength: source_linked
- Finding: release_recency=unknown。
- User impact: May increase setup, validation, or first-run risk for the user.
- Evidence: evidence.maintainer_signals | github_repo:1201173969 | https://github.com/JuliusBrussee/caveman
