资源清单申请了不必要的文件写入、Git 和命令执行权限
原文依据:4 处该 Skill 的声明目的只是提供 Go 资讯和学习资源,但 allowed-tools 同时包含 Edit、Write、Git 和 Go 命令以及 Agent。正文所示工作不需要修改用户项目或运行开发命令。
若宿主把该字段当作授权范围,启用 Skill 的代理可能具备修改项目文件、改变 Git 工作区或运行 Go 命令的能力;这些后果明显超出查阅资源的需要。仅凭这些行不能证明任何命令已经执行。
该 Skill 的实际内容是 Go 资讯来源与关注对象清单,但其活动权限还包括编辑/写入文件、运行 Go、golangci-lint 和 Git 命令,以及启动 Agent。正文没有给出需要这些权限的工作流程。若宿主按此声明授权,Skill 被调用时可能拥有修改用户项目或执行 Git 操作的能力,超出提供资源建议所需范围。用户可要求作者缩减为只读和必要的网络检索权限,并在隔离环境中禁用写入与命令执行。
---name: golang-stay-updateddescription: "Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeking Golang learning resources, discovering new libraries or tools, finding community channels or meetups, picking Go people to follow, or keeping up with Go language changes and releases. Not for querying a specific module's versions, docs, or vulnerabilities from the CLI (→ See `samber/cc-skills-golang@golang-pkg-go-dev` skill)."user-invocable: true查看另外 3 个位置
install: []allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch WebSearch---name: golang-stay-updateddescription: "Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeking Golang learning resources, discovering new libraries or tools, finding community channels or meetups, picking Go people to follow, or keeping up with Go language changes and releases. Not for querying a specific module's versions, docs, or vulnerabilities from the CLI (→ See `samber/cc-skills-golang@golang-pkg-go-dev` skill)."user-invocable: trueA curated guide to keeping your finger on the pulse of the Go ecosystem.