T05 · Unauthorized Access and Privilege Escalation
Warning
- Location
SKILL.md:17- Finding
Overly Broad Tool Permissions Violate Least Privilege
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Go style skill is not malicious, but it requests broad ability to edit files, run Go/Git/linter commands, and delegate to agents beyond what style guidance clearly needs.
Install this only if you are comfortable letting the agent modify Go project files and potentially run Go, Git, and golangci-lint commands. For untrusted repositories or review-only use, prefer a read-only or approval-gated configuration and avoid remote Git operations, generators, tests, or linters that execute repository-controlled code.
SKILL.md:17Overly Broad Tool Permissions Violate Least Privilege
No suspicious patterns detected.