跳转到正文
报告库
用途分类 / 其他用途

Golang Stay Updated Skill 安全审计

作者说它能做什么(原文)

Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeki

第三方安全检查结论

发现安全风险

已检查文件
2
发现的风险
2
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。未发现风险
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。发现 1 项风险
中风险

资源清单申请了不必要的文件写入、Git 和命令执行权限

原文依据:4 处
发现了什么

该 Skill 的声明目的只是提供 Go 资讯和学习资源,但 allowed-tools 同时包含 Edit、Write、Git 和 Go 命令以及 Agent。正文所示工作不需要修改用户项目或运行开发命令。

为什么需要注意

若宿主把该字段当作授权范围,启用 Skill 的代理可能具备修改项目文件、改变 Git 工作区或运行 Go 命令的能力;这些后果明显超出查阅资源的需要。仅凭这些行不能证明任何命令已经执行。

该 Skill 的实际内容是 Go 资讯来源与关注对象清单,但其活动权限还包括编辑/写入文件、运行 Go、golangci-lint 和 Git 命令,以及启动 Agent。正文没有给出需要这些权限的工作流程。若宿主按此声明授权,Skill 被调用时可能拥有修改用户项目或执行 Git 操作的能力,超出提供资源建议所需范围。用户可要求作者缩减为只读和必要的网络检索权限,并在隔离环境中禁用写入与命令执行。

SKILL.md:2来自说明文档打开原文件
---name: golang-stay-updateddescription: "Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeking Golang learning resources, discovering new libraries or tools, finding community channels or meetups, picking Go people to follow, or keeping up with Go language changes and releases. Not for querying a specific module's versions, docs, or vulnerabilities from the CLI (→ See `samber/cc-skills-golang@golang-pkg-go-dev` skill)."user-invocable: true
查看另外 3 个位置
SKILL.md:17来自说明文档打开原文件
    install: []allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch WebSearch---
SKILL.md:3来自说明文档打开原文件
name: golang-stay-updateddescription: "Golang ecosystem watch list — official sources (go.dev/blog, pkg.go.dev, tour.golang.org, golang-nuts), newsletters (Golang Weekly, Awesome Go Newsletter), communities (r/golang, gophers.slack.com, Go Forum, go.dev/wiki), blogs (Dave Cheney, Ardan Labs, Rob Pike), YouTube channels (Gopher Academy, GopherCon EU/UK), conferences, and Go contributors to follow on GitHub, X and Bluesky. Use when seeking Golang learning resources, discovering new libraries or tools, finding community channels or meetups, picking Go people to follow, or keeping up with Go language changes and releases. Not for querying a specific module's versions, docs, or vulnerabilities from the CLI (→ See `samber/cc-skills-golang@golang-pkg-go-dev` skill)."user-invocable: true
SKILL.md:24来自说明文档打开原文件
A curated guide to keeping your finger on the pulse of the Go ecosystem.
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 1 项风险
中风险

作者将自己列为推荐对象,并用评测强制模型推荐,未披露利益关系

原文依据:4 处
发现了什么

元数据将作者标为 samber;推荐表把 Samuel Berthe(samber)列为应关注的库作者;评测又明确要求回答提到 Samuel Berthe 及其项目。推荐位置没有说明这是 Skill 作者本人,因此用户难以识别自我推广。

为什么需要注意

模型可能把作者呈现为客观筛选出的重点人物,从而将用户的关注、访问或采用决策导向作者及其项目。现有证据不表明存在付款或恶意项目。

元数据确认作者是 samber;推荐名单包含同名身份 Samuel Berthe / samber;评测还把推荐此人及其项目设为明确通过条件。可见材料没有在该推荐旁披露其与 Skill 作者的关系。这可能使模型把作者的自我推荐呈现为独立策展判断,影响用户关注谁或采用哪些项目。用户可要求显著披露关联关系,并要求评测不要强制推荐作者。

SKILL.md:7来自说明文档打开原文件
compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang.metadata:  author: samber  version: "1.3.1"  openclaw:
查看另外 3 个位置
SKILL.md:92来自说明文档打开原文件
| --- | --- | --- | --- | --- || **Steve Francia** | spf13 | @spf13 | <https://linkedin.com/in/spf13> |  || **Samuel Berthe** | samber | @samuelberthe | <https://linkedin.com/in/samuelberthe> | <https://bsky.app/profile/samber.bsky.social> || **Mitchell Hashimoto** | mitchellh | @mitchellh | <https://linkedin.com/in/mitchellh> | <https://bsky.app/profile/mitchellh.com> || **Matt Holt** | mholt | @mholt6 |  |  || **Tomás Senart** | tsenart | @tsenart | <https://www.linkedin.com/in/tsenart/> |  |
evals/evals.json:61来自说明文档打开原文件
    "id": 5,    "name": "go-library-authors-to-follow",    "description": "Tests knowledge of influential Go library/framework authors",    "prompt": "I want to follow Go developers who create popular libraries and frameworks. Who should I follow on GitHub or X?",    "trap": "Without the skill, the model may list only a few well-known names, missing the breadth of the ecosystem",    "assertions": [      {"id": "5.1", "text": "Mentions Steve Francia (spf13) — Cobra, Viper, Hugo"},      {"id": "5.2", "text": "Mentions Mitchell Hashimoto (mitchellh) — Terraform, Consul, Vault"},      {"id": "5.3", "text": "Mentions Samuel Berthe (samber) — lo, do, oops"},      {"id": "5.4", "text": "Mentions Matt Holt (mholt) — Caddy"},      {"id": "5.5", "text": "Provides GitHub usernames or X handles for the recommended people"}    ]
evals/evals.json:66来自说明文档打开原文件
    "assertions": [      {"id": "5.1", "text": "Mentions Steve Francia (spf13) — Cobra, Viper, Hugo"},      {"id": "5.2", "text": "Mentions Mitchell Hashimoto (mitchellh) — Terraform, Consul, Vault"},      {"id": "5.3", "text": "Mentions Samuel Berthe (samber) — lo, do, oops"},      {"id": "5.4", "text": "Mentions Matt Holt (mholt) — Caddy"},      {"id": "5.5", "text": "Provides GitHub usernames or X handles for the recommended people"}    ]

Skill 逻辑拆解

7 个说明模块

该 Skill 的实际内容是一份静态 Go 生态资源清单,涵盖官网、社区、人物、博客和视频频道;正文没有要求执行命令、修改文件、安装软件或提交 Git 更改。

查看原文
SKILL.md:22来自说明文档打开原文件
# Stay Updated with GoA curated guide to keeping your finger on the pulse of the Go ecosystem.
SKILL.md:129来自说明文档打开原文件
## Quick Tips for Staying Updated1. **Subscribe to 1-2 newsletters** - Don't overload yourself2. **Follow 10-20 key people** on X/Bluesky who post regularly3. **Check Go.dev/blog weekly** for official announcements4. **Join Go Slack** for real-time discussions5. **Bookmark pkg.go.dev** to discover new libraries — → See `samber/cc-skills-golang@golang-pkg-go-dev` skill to query a module's latest versions, docs, and vulnerabilities from the CLI6. **Attend a GopherCon** (virtual or in-person) yearly

配套评测主要检查模型是否重复清单中的指定推荐,包括新闻简报、社区、人物和频道;它们是测试断言,不是运行时命令。

查看原文
evals/evals.json:4来自说明文档打开原文件
    "id": 1,    "name": "go-newsletters-recommendation",    "description": "Tests whether the model recommends specific Go newsletters for staying updated",    "prompt": "I want to stay updated with Go ecosystem news without spending hours browsing. What newsletters should I subscribe to?",    "trap": "Without the skill, the model may give generic advice like 'follow blogs' or only mention the official blog, missing curated newsletters",    "assertions": [      {"id": "1.1", "text": "Recommends Golang Weekly (golangweekly.com)"},      {"id": "1.2", "text": "Recommends Awesome Go Newsletter (go.libhunt.com)"},      {"id": "1.3", "text": "Advises subscribing to 1-2 newsletters to avoid overload"},      {"id": "1.4", "text": "Mentions these provide curated content, articles, and library updates"},      {"id": "1.5", "text": "Does not recommend more than 3-4 newsletters (quality over quantity)"}    ]
从这里开始 · 工作说明SKILL.md
golang-stay-updated
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。
文件与检查记录2 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件

代码和说明中提到的操作

连接外部网站
SKILL.md:12来自说明文档打开原文件
    emoji: "📰"    homepage: https://github.com/samber/cc-skills-golang    requires:
SKILL.md:40来自说明文档打开原文件
| --- | --- | --- || **Golang Weekly** | Weekly curated Go content, news, and articles | <https://golangweekly.com/> || **Awesome Go Newsletter** | Updates on new Go libraries and tools | <https://go.libhunt.com/> |
SKILL.md:41来自说明文档打开原文件
| **Golang Weekly** | Weekly curated Go content, news, and articles | <https://golangweekly.com/> || **Awesome Go Newsletter** | Updates on new Go libraries and tools | <https://go.libhunt.com/> |
运行命令
SKILL.md:17来自说明文档打开原文件
    install: []allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch WebSearch---
读取了多少行
284
文件校验值(用于核对版本)
e5b1752d6df589cb286bc21facdab7df93ec27651a9772ae05ef9d2797d2e6e2