पाठ 19 / 26
Skill install या merge करने से पहले समीक्षा Checklist
भरोसा करने से पहले पढ़ें कि skill Claude से क्या करवाएगी।
हर file पढ़ें, ख़ासकर scripts और allowed-tools
अपनी टीम के बाहर की skill install करने, या pull request में merge करने से पहले सब कुछ पढ़ें: SKILL.md (वह क्या निर्देश देती है, और क्या वह उसके description से मेल खाता है?), हर script (वह क्या पढ़ती, लिखती, हटाती या network पर भेजती है?), allowed-tools सूची (क्या संकरी है?), और संदर्भित URLs व डाउनलोड। चेतावनी संकेत: सुरक्षा जाँचें बंद करने या अन्य नियम अनदेखे करने के निर्देश; secrets या tokens की माँग; ऐसी commands जो कोड डाउनलोड कर चलाती हैं; skill के उद्देश्य से बाहर की files छूने वाली scripts; छिपाया या encoded पाठ; description जो कुछ और दावा करे जबकि body कुछ और करे; और व्यापक पूर्व-अनुमोदित tools। सत्यापन-योग्य स्रोतों की skills पसंद करें, दिखते इतिहास और maintainers सहित, विशिष्ट commit या संस्करण पर pin करें, और अपरिचित skills पहले credentials रहित sandbox या container में चलाएँ। कुछ गड़बड़ लगे तो install न करें।
Skill समीक्षा checklist
जो skill आपने नहीं लिखी उसके लिए उपयोग करें।
[ ] source verifiable (maintainer, history); pinned to a commit/version
[ ] SKILL.md read in full: does the body match the description?
[ ] every script read: what does it read / write / delete / send?
[ ] allowed-tools narrow (specific script, read-only where possible)
[ ] no download-and-execute, no obfuscated or encoded blobs
[ ] no requests for secrets, tokens, or to disable checks
[ ] referenced URLs and files all legitimate and necessary
[ ] first run in a sandbox / container with no credentialsअपरिचित skills पहले sandbox में चलाएँ
Credentials रहित container गड़बड़ होने पर नुक़सान सीमित रखता है।
त्वरित जाँच: कौन-सा निष्कर्ष आपको skill अस्वीकार करने को प्रेरित करे?
- Template file
- साफ़ README
- छोटा description
- Setup चरण जो दूरस्थ script डाउनलोड कर shell में pipe करता है
Answer
Setup चरण जो दूरस्थ script डाउनलोड कर shell में pipe करता है — Download-and-execute स्रोत को आपकी मशीन पर पूरा नियंत्रण देता है।