The resource directory requests unnecessary file-write, Git, and command-execution permissions
Source references: 4The stated purpose is to provide Go news and learning resources, yet `allowed-tools` includes Edit, Write, Git and Go commands, plus Agent. The workflow shown in the body does not require modifying the user’s project or running development commands.
If the host treats this field as an authorization boundary, an agent using the Skill could modify project files, alter the Git working tree, or execute Go commands—effects well beyond consulting a resource list. These lines do not show that any command has actually run.
The Skill is a curated list of Go news sources and people to follow, yet it requests file editing/writing, Go, golangci-lint and Git command execution, plus Agent access. No workflow in the body shows why these capabilities are needed. If the host grants the declaration, invocation could expose the user's project to modification or Git operations beyond what resource recommendations require. A user can ask the author to limit it to read-only and necessary web-retrieval access, and disable writes and command execution in the host.
---name: golang-stay-updateddescription: "Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeking Golang learning resources, discovering new libraries or tools, finding community channels or meetups, picking Go people to follow, or keeping up with Go language changes and releases. Not for querying a specific module's versions, docs, or vulnerabilities from the CLI (→ See `samber/cc-skills-golang@golang-pkg-go-dev` skill)."user-invocable: trueShow 3 other places
install: []allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch WebSearch---name: golang-stay-updateddescription: "Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeking Golang learning resources, discovering new libraries or tools, finding community channels or meetups, picking Go people to follow, or keeping up with Go language changes and releases. Not for querying a specific module's versions, docs, or vulnerabilities from the CLI (→ See `samber/cc-skills-golang@golang-pkg-go-dev` skill)."user-invocable: trueA curated guide to keeping your finger on the pulse of the Go ecosystem.