Go 安装

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Go installer guide with normal cautions about changing shell startup settings.

Before installing, confirm your CPU architecture, download only from go.dev, consider verifying the Go checksum, and check whether ~/.bashrc already has Go-related PATH, GOPATH, or GOROOT entries so you can avoid duplicates or remove the added lines later if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the user to append environment-variable exports directly to ~/.bashrc or ~/.profile, creating persistent shell changes without any warning, backup step, or scoping guidance. While the commands themselves are not overtly malicious, persistent modification of startup files can unexpectedly affect future shells, CI jobs, and other tooling, especially if users copy-paste blindly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal