Back to skill

Security audit

golang-stay-updated

Security checks across malware telemetry and agentic risk

Overview

The skill content is a harmless Go resource guide, but it asks for broad editing, shell, git, and agent permissions that are not needed for that purpose.

Install only if you are comfortable with this skill declaring broader agent permissions than its resource-guide purpose requires. The guide content appears benign, but the publisher should narrow the allowed tools or explain why editing, shell, git, and Agent access are necessary.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill is described as a passive, curated guide to Go news and community resources, but it declares powerful capabilities including file reading/writing, code execution via Bash(go:*), git operations, and agent/web access. This violates least privilege: if the skill is invoked or extended in an unsafe workflow, those unnecessary tools could be abused to modify files, execute commands, or access data unrelated to the stated purpose.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.