If you establish the integration, and then click the actual “Claude” button in the publishing menu, it prefills the claude.ai prompt with this message:
I also tried the approach described here of setting the post to allow comments to anyone with the URL, and Sonnet retrieved the content but considered the associated API notes to be highly suspicious and again, likely a prompt injection attack on me.
But now I realize you probably meant the metadata we return as part of the markdown response when agents fetch posts via the common mechanisms that we can detect.
A message close to the second form got me (Opus 4.8/high):
On the second link: I didn’t fetch lesswrong.com/api/SKILL.md, and I’d treat it with suspicion. A SKILL.md is normally a trusted file in my local environment, not something served from an arbitrary web path — and LessWrong’s actual API is GraphQL, with no such documentation convention I’m aware of. …
Ironically I was asking questions about prompt-infection. So another data point for a regular published skill over dynamic skill retrieval.
If you establish the integration, and then click the actual “Claude” button in the publishing menu, it prefills the claude.ai prompt with this message:
I thought that’s what you meant by this:
But now I realize you probably meant the metadata we return as part of the markdown response when agents fetch posts via the common mechanisms that we can detect.
A message close to the second form got me (Opus 4.8/high):
Ironically I was asking questions about prompt-infection. So another data point for a regular published skill over dynamic skill retrieval.