Add /learn - cross-platform skill discovery with security scanning#12
Add /learn - cross-platform skill discovery with security scanning#12romainsimon wants to merge 2 commits intoblock:mainfrom
Conversation
✅ Validate Skills — PASSEDSummary: FAIL=0 · WARN=0 Output (last 200 lines) |
🛡️ Skills Security Scan — FAILSummary: FAIL=5 · WARN=43 · FILES=2 ❌ FAIL blocks merge. Fix the items below. ❌ Failureslearn
Guidance: Blocks prompt-injection language combined with secret-target keywords.
Guidance: Blocks download-and-execute. Vendor scripts or verify pinned downloads + checksums.
Guidance: Blocks download-and-execute. Vendor scripts or verify pinned downloads + checksums.
Guidance: Blocks download-and-execute. Vendor scripts or verify pinned downloads + checksums.
Guidance: Blocks prompt-injection language combined with secret-target keywords.
|
|
Fixed the issues flagged by the validator:
The skill now references the external file for detailed patterns rather than listing them inline. |
Search and install from 40,000+ skills with two-layer security: - Server-side scanning (12 threat categories) - Client-side verification before install - Auto-rating feedback loop surfaces quality skills Works with Goose, Claude Code, Cursor, Codex, Windsurf, and 10+ more. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> Signed-off-by: Romain SIMON <contact@romainsimon.net>
- Move inline dangerous patterns to references/SECURITY.md - Keep high-level threat categories and scoring in SKILL.md - Patterns are now referenced, not inline (avoids false positives) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> Signed-off-by: Romain SIMON <contact@romainsimon.net>
01b4bed to
50e6620
Compare
Summary
Adds
/learn, a cross-platform skill discovery and installation tool powered by agentskill.sh.What it does
Commands
/learn seo/learn @owner/name/learn/learn trending/learn scan <path>/learn list/learn updateWhy include this?
After ClawHub's malware incident (20% malicious skills), security-first discovery matters. This gives Goose users access to a pre-vetted, cross-platform skill ecosystem.
Security dashboard