Golang Naming

Security checks across malware telemetry and agentic risk

Overview

This appears to be a benign Go naming-convention guide, with a minor note that it can guide file edits and run Go/Git-related tools when active.

This skill looks safe to install as a Go naming/style reference. Because it can be active during coding and has edit plus Go/Git tool permissions, review changes before applying them, especially in important repositories.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI02: Tool Misuse and Exploitation
Low
What this means

When active, the coding agent may apply naming guidance by modifying project files or running repository-related commands.

Why it was flagged

The skill is primarily a Go naming guide, but it declares authority to read, edit, and write files, run Go/lint/Git commands, and use an Agent tool. This is purpose-aligned for code review or refactoring, but users should notice it is not purely read-only guidance.

Skill content
allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent
Recommendation

Use it in intended Go projects only, and review diffs and any proposed Go/Git commands before accepting changes.