@samber

创作者 · samber

最近更新 · 2026年8月24日

golang-naming

审查 · 69已收录

Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and subtest names. Use this skill when writing new Go code, reviewing or refactoring,

OpenAgentSkill 信任评分
69/100

仅限沙盒

质量82/100
审计83/100
Stars3.1K
Verified installs0

安装目标

Codex 安装提示词

Install the "golang-naming" agent skill from https://github.com/samber/cc-skills-golang/tree/main/skills/golang-naming. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and subtest names. Use this skill when writing new Go code, reviewing or refactoring, choosing between naming alternatives (New vs NewTypeName, isConnected vs connected, ErrNotFound vs NotFoundError, StatusReady vs StatusUnknown at iota 0), debating Go package names (utils/helpers anti-patterns), or asking about Go naming best practices. Also trigger when the user mentions MixedCaps vs snake_case, ALL_CAPS constants, Get-prefix on getters, or error string casing. Do NOT use for general Go implementation questions that don't involve naming decisions. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"samber-golang-naming","task":"Install golang-naming","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.

供给资产档案

编程与开发 Agent

代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。

浏览赛道

场景

编程 Agent

我需要一个能理解仓库、修改代码并审查 Pull Request 的编程 Agent。

适配 Agent

Claude Code + OpenAI Agents + CLI

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add samber/cc-skills-golang --skill golang-naming

维护状态

新鲜

今天有推送

风险

需审查

Dependency or permission surface needs review

GitHub 质量

3.1K

82/100 质量 · 77/100 信任

覆盖标签

编程编程 Agent编程 Agentagent-skill

审查说明

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

82

可靠的选择,值得加入生产工作流候选列表。

信任

仅限沙盒
69

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

审计

需审查
83

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

安装前需人工审查

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

3.1K 个 GitHub Stars

仓库活跃度

3.1K 个 Star,204 个 Fork

维护状态

今天有推送

许可证

MIT

安装

npx skills add samber/cc-skills-golang --skill golang-naming

安装安全性

标准软件包或运行时安装路径

权限范围

secrets or environment access, shell or command execution

Agent 结果

暂未有 Agent 结果数据

文档

README/SKILL.md 上下文充分

风险摘要

生产前审查

  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 已声明许可证
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

View technical data+

适用任务

  • 编程 Agent 工作流
  • Claude Code 团队
  • 重视 GitHub 采用信号的团队
  • Inspect source files

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

安装决策

命令
npx skills add samber/cc-skills-golang --skill golang-naming
策略
审查
人工审查

信任与风险

信任
69/100
审计
83/100
风险级别
需审查

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add samber/cc-skills-golang --skill golang-naming

不适用场景

  • 需要厂商支持 SLA 的团队
  • 没有内部安全审查的高合规环境
  • 暂未有 OpenAgentSkill 使用反馈数据
  • 高风险权限提示:Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent 安全 v2

43/100 · 避免自动安装

实验性审查

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

通过 API 解析

Shell 或命令执行

Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

  • 高风险权限提示:Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use golang-naming in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20golang-naming%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/samber-golang-naming/install
Install command: npx skills add samber/cc-skills-golang --skill golang-naming
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use golang-naming for this task. Review https://www.openagentskill.com/api/skills/samber-golang-naming/install, then install with: npx skills add samber/cc-skills-golang --skill golang-naming

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

93/100

编程 Agent

平台

Claude Code, OpenAI Agents

审计报告

需审查 · 83/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

适合 编程 Agent 的首选

将其作为优先候选,再在你的 Agent 环境中验证 README 与安装路径。

93
就绪度
采用
阶段

栈中角色

首选

主要匹配

编程 Agent

信任标签

可用于生产

安装路径

命令已就绪

适用场景

  • 编程 Agent 工作流
  • Claude Code 团队
  • 重视 GitHub 采用信号的团队

证据

  • 3,056 个 GitHub Stars
  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 82/100 质量档案

先审查

  • 暂未有 OpenAgentSkill 使用反馈数据

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次编程 Agent任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

仅限沙盒

有用但信任信号不足或混杂的候选项。在结果闭环证明任务匹配前,请保持在隔离工作区内使用。

69
OpenAgentSkill 信任评分

GitHub 采用度

通过

3.1K 个 GitHub Stars

Star/Fork 活跃度

信息

3.1K 个 Star,204 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

今天有推送

许可证清晰度

通过

MIT

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • 有意义的 GitHub 采用信号
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

仅在沙盒中运行,并在用于真实工作前比较接近的替代方案。

质量档案

适用于 Agent 工作流的候选

可靠的选择,值得加入生产工作流候选列表。

82
GitHub Stars
3.1K
新鲜度
今天
安装就绪
许可证
MIT

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: golang-naming description: "Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and subtest names. Use this skill when writing new Go code, reviewing or refactoring, choosing between naming alternatives (New vs NewTypeName, isConnected vs connected, ErrNotFound vs NotFoundError, StatusReady vs StatusUnknown at iota 0), debating Go package names (utils/helpers anti-patterns), or asking about Go naming best practices. Also trigger when the user mentions MixedCaps vs snake_case, ALL_CAPS constants, Get-prefix on getters, or error string casing. Do NOT use for general Go implementation questions that don't involve naming decisions." user-invocable: true license: MIT compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang. metadata: author: samber version: "1.2.0" openclaw: emoji: "🏷" homepage: https://github.com/samber/cc-skills-golang requires: bins: - go install: [] allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent paths: - "**/*.go" ---

> **Community default.** A company skill that explicitly supersedes `samber/cc-skills-golang@golang-naming` skill takes precedence.

# Go Naming Conventions

Go favors short, readable names. Capitalization controls visibility — uppercase is exported, lowercase is unexported. All identifiers MUST use MixedCaps, NEVER underscores.

> "Clear is better than clever." — Go Proverbs > > "Design the architecture, name the components, document the details." — Go Proverbs

To ignore a rule, just add a comment to the code.

## Quick Reference

| Element | Convention | Example | | --- | --- | --- | | Package | lowercase, single word, \_test suffix OK for test files | `json`, `http`, `tabwriter`, `http_test` | | File | lowercase, underscores OK | `user_handler.go` | | Exported name | UpperCamelCase | `ReadAll`, `HTTPClient` | | Unexported | lowerCamelCase | `parseToken`, `userCount` | | Interface | method name + `-er` | `Reader`, `Closer`, `Stringer` | | Struct | MixedCaps noun | `Request`, `FileHeader` | | Constant | MixedCaps (not ALL_CAPS) | `MaxRetries`, `defaultTimeout` | | Receiver | 1-2 letter abbreviation | `func (s *Server)`, `func (b *Buffer)` | | Error variable | `Err` prefix | `ErrNotFound`, `ErrTimeout` | | Error type | `Error` suffix | `PathError`, `SyntaxError` | | Constructor | `New` (single type) or `NewTypeName` (multi-type) | `ring.New`, `http.NewRequest` | | Boolean field | `is`, `has`, `can` prefix on **fields** and methods | `isReady`, `IsConnected()` | | Test function | `Test` + function name | `TestParseToken` | | Acronym | all caps or all lower | `URL`, `HTTPServer`, `xmlParser` | | Variant: context | `WithContext` suffix | `FetchWithContext`, `QueryContext` | | Variant: in-place | `In` suffix | `SortIn()`, `ReverseIn()` | | Variant: error | `Must` prefix | `MustParse()`, `MustLoadConfig()` | | Option func | `With` + field name | `WithPort()`, `WithLogger()` | | Enum (iota) | type name prefix, zero-value = unknown | `StatusUnknown` at 0, `StatusReady` | | Named return | descriptive, for docs only | `(n int, err error)` | | Error string | lowercase (incl. acronyms), no punctuation | `"image: unknown format"`, `"invalid id"` | | Import alias | short, only on collision | `mrand "math/rand"`, `pb "app/proto"` | | Format func | `f` suffix | `Errorf`, `Wrapf`, `Logf` | | Test table fields | `got`/`expected` prefixes | `input string`, `expected int` |

## MixedCaps

All Go identifiers MUST use `MixedCaps` (or `mixedCaps`). NEVER use underscores in identifiers — the only exceptions are test function subcases (`TestFoo_InvalidInput`), generated code, and OS/cgo interop. This is load-bearing, not cosmetic — Go's export mechanism relies on capitalization, and tooling assumes MixedCaps throughout.

```go // ✓ Good MaxPacketSize userCount parseHTTPResponse

// ✗ Bad — these conventions conflict with Go's export mechanism and tooling expectations MAX_PACKET_SIZE // C/Python style max_packet_size // snake_case kMaxBufferSize // Hungarian notation ```

## Avoid Stuttering

Go call sites always include the package name, so repeating it in the identifier wastes the reader's time — `http.HTTPClient` forces parsing "HTTP" twice. A name MUST NOT repeat information already present in the package name, type name, or surrounding context.

```go // Good — clean at the call site http.Client // not http.HTTPClient json.Decoder // not json.JSONDecoder user.New() // not user.NewUser() config.Parse() // not config.ParseConfig()

// In package sqldb: type Connection struct{} // not DBConnection — "db" is already in the package name

// Anti-stutter applies to ALL exported types, not just the primary struct: // In package dbpool: type Pool struct{} // not DBPool type Status struct{} // not PoolStatus — callers write dbpool.Status type Option func(*Pool) // not PoolOption ```

## Frequently Missed Conventions

These conventions are correct but non-obvious — they are the most common source of naming mistakes:

**Constructor naming:** When a package exports a single primary type, the constructor is `New()`, not `NewTypeName()`. This avoids stuttering — callers write `apiclient.New()` not `apiclient.NewClient()`. Use `NewTypeName()` only when a package has multiple constructible types (like `http.NewRequest`, `http.NewServeMux`).

**Boolean struct fields:** Unexported boolean fields MUST use `is`/`has`/`can` prefix — `isConnected`, `hasPermission`, not bare `connected` or `permission`. The exported getter keeps the prefix: `IsConnected() bool`. This reads naturally as a question and distinguishes booleans from other types.

**Error strings are fully lowercase — including acronyms.** Write `"invalid message id"` not `"invalid message ID"`, because error strings are often concatenated with other context (`fmt.Errorf("parsing token: %w", err)`) and mixed case looks wrong mid-sentence. Sentinel errors should include the package name as prefix: `errors.New("apiclient: not found")`.

**Enum zero values:** Always place an explicit `Unknown`/`Invalid` sentinel at iota position 0. A `var s Status` silently becomes 0 — if that maps to a real state like `StatusReady`, code can behave as if a status was deliberately chosen when it wasn't.

**Subtest names:** Table-driven test case names in `t.Run()` should be fully lowercase descriptive phrases: `"valid id"`, `"empty input"` — not `"valid ID"` or `"Valid Input"`.

## Detailed Categories

For complete rules, examples, and rationale, see:

- **[Packages, Files & Import Aliasing](./references/packages-files.md)** — Package naming (single word, lowercase, no plurals), file naming conventions, import alias patterns (only use on collision to avoid cognitive load), and directory structure.

- **[Variables, Booleans, Receivers & Acronyms](./references/identifiers.md)** — Scope-based naming (length matches scope: `i` for 3-line loops, longer names for package-level), single-letter receiver conventions (`s` for Server), acronym casing (URL not Url, HTTPServer not HttpServer), and boolean naming patterns (isReady, hasPrefix).

- **[Functions, Methods & Options](./references/functions-methods.md)** — Getter/setter patterns (Go omits `Get` so `user.Name()` reads naturally), constructor conventions (`New` or `NewTypeName`), named returns (for documentation only), format function suffixes (`Errorf`, `Wrapf`), and functional options (`WithPort`, `WithLogger`).

- **[Types, Constants & Errors](./references/types-errors.md)** — Interface naming (`Reader`, `Closer` suffix with `-er`), struct naming (nouns, MixedCaps), constants (MixedCaps, not ALL_CAPS), enums (type name prefix like `StatusReady`), sentinel errors (`ErrNotFound` variables), error types (`PathError` suffix), and error message conventions (lowercase, no punctuation).

- **[Test Naming](./references/testing.md)** — Test function naming (`TestFunctionName`), table-driven test field conventions (`input`, `expected`), test helper naming, and subcase naming patterns.

## Common Mistakes

| Mistake | Fix | | --- | --- | | `ALL_CAPS` constants | Go reserves casing for visibility, not emphasis — use `MixedCaps` (`MaxRetries`) | | `GetName()` getter | Go omits `Get` because `user.Name()` reads naturally at call sites. But `Is`/`Has`/`Can` prefixes are kept for boolean predicates: `IsHealthy() bool` not `Healthy() bool` | | `Url`, `Http`, `Json` acronyms | Mixed-case acronyms create ambiguity (`HttpsUrl` — is it `Https+Url`?). Use all caps or all lower | | `this` or `self` receiver | Go methods are called frequently — use 1-2 letter abbreviation (`s` for `Server`) to reduce visual noise | | `util`, `helper` packages | These names say nothing about content — use specific names that describe the abstraction | | `http.HTTPClient` stuttering | Package name is always present at call site — `http.Client` avoids reading "HTTP" twice | | `user.NewUser()` constructor | Single primary type uses `New()` — `user.New()` avoids repeating the type name | | `connected bool` field | Bare adjective is ambiguous — use `isConnected` so the field reads as a true/false question | | `"invalid message ID"` error | Error strings must be fully lowercase including acronyms — `"invalid message id"` | | `StatusReady` at iota 0 | Zero value should be a sentinel — `StatusUnknown` at 0 catches uninitialized values | | `"not found"` error string | Sentinel errors should include the package name — `"mypackage: not found"` identifies the origin | | `userSlice` type-in-name | Types encode implementation detail — `users` describes what it holds, not how | | Inconsistent receiver names | Switching names across methods of the same type confuses readers — use one name consistently | | `snake_case` identifiers | Underscores conflict with Go's MixedCaps convention and tooling expectations — use `mixedCaps` | | Long names for short scopes | Name length should match scope — `i` is fine for a 3-line loop, `userIndex` is noise | | Naming constants by value | Values change, roles don't — `DefaultPort` survives a port change, `Port8080` doesn't | | `FetchCtx()` context variant | `WithContext` is the standard Go suffix — `FetchWithContext()` is instantly recognizable | | `sort()` in-place but no `In` | Readers assume functions return new values. `SortIn()` signals mutation | | `parse()` panicking on error | `MustParse()` warns callers that failure panics — surprises belong in the name | | Mixing `With*`, `Set*`, `Use*` | Consistency across the codebase — `With*` is the Go convention for functional options | | Plural package names | Go convention is singular (`net/url` not `net/urls`) — keeps import paths consistent | | `Wrapf` without `f` suffix | The `f` suffix signals format-string semantics — `Wrapf`, `Errorf` tell callers to pass format args | | Unnecessary import aliases | Aliases add cognitive load. Only alias on collision — `mrand "math/rand"` | | Inconsistent concept names | Using `user`/`account`/`person` for the same concept forces readers to track synonyms — pick one name |

Applying these fixes means renaming existing identifiers — → See `samber/cc-skills-golang@golang-gopls` skill to do it safely: its rename updates every call site across the workspace and refuses a rename that would break interface satisfaction, which a grep/sed or manual Edit-based rename silently misses.

## Enforce with Linters

Many naming convention issues are caught automatically by linters: `revive`, `predeclared`, `misspell`, `errname`. See `samber/cc-skills-golang@golang-lint` skill for configuration and usage.

## Cross-References

- → See `samber/cc-skills-golang@golang-code-style` skill for broader formatting and style decisions - → See `samber/cc-skills-golang@golang-structs-interfaces` skill for interface naming depth and receiv

技术详情

版本
1.0.0
许可证
MIT
最近更新
2026年8月24日
发布时间
2026年8月24日

决策摘要

首选

93
就绪
采用
阶段

3,056 个 GitHub Stars

审计

安装审查

安装与采用审查

83
需审查
安全性
77/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 golang-naming 准备的场景化草稿,可手动发布到 X。

策展说明
golang-naming: Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constant...

3.1K stars

https://www.openagentskill.com/skills/samber-golang-naming?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for golang-naming:
https://www.openagentskill.com/skills/samber-golang-naming?ref=x

Install: npx skills add samber/cc-skills-golang --skill golang-naming
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
samber
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 samber,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/samber-golang-naming?metric=listed&label=Listed)](https://www.openagentskill.com/skills/samber-golang-naming)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/samber-golang-naming?metric=trust&label=Trust)](https://www.openagentskill.com/skills/samber-golang-naming)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/samber-golang-naming?metric=audit&label=Audit)](https://www.openagentskill.com/skills/samber-golang-naming/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/samber-golang-naming?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/samber-golang-naming)

作者

S

samber

@samber

健康信号

GitHub Stars
3.1K
质量评分
48/100
最近 GitHub 推送
2026年8月24日
框架提示
未知
OpenAgentSkill 浏览量
0
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

仅限沙盒

69
  • GitHub 采用度3.1K 个 GitHub Stars通过
  • Star/Fork 活跃度3.1K 个 Star,204 个 Fork; 当前元数据中没有议题活跃度信息信息
  • 近期维护今天有推送通过
  • 许可证清晰度MIT通过
  • README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
  • 依赖与运行时风险command execution surface, credential or environment access检查