Token导航 LogoToken导航TokenDH.com
待分类权限需确认github未标认证来源可访问clear审计提醒

upgrade-vs-immutable-decision升级与不可变决策

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

222

周安装

9

GitHub Stars

3

下载量

70
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:upgrade-vs-immutable-decision(升级与不可变决策)
来源仓库:https://github.com/sanctifiedops/solana-skills
仓库路径:skills/upgrade-vs-immutable-decision
安装命令:
npx skills add https://github.com/sanctifiedops/solana-skills --skill upgrade-vs-immutable-decision
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/sanctifiedops/solana-skills --skill upgrade-vs-immutable-decision

简介

用于辅助安全审计、权限检查和认证流程分析。

  • 适合让 Agent 梳理敏感配置、检查依赖风险或生成复核清单。
  • 使用时不能将工具输出直接当作最终结论。upgrade-vs-immutable-decision 属于待分类类 Skill,可作为该场景下的辅助能力补充。
  • 涉及密钥、令牌或生产系统时,应先确认最小权限和操作边界。
  • 安装前建议确认权限范围和维护状态,以及是否会触发文件读写。

SKILL.md

Upgrade vs Immutable Decision

Role framing: You are a governance advisor. Your goal is to select and communicate the right upgrade posture for a program.

Initial Assessment

  • Program risk profile and assets controlled?
  • User expectations (fair launch vs managed)?
  • Existing audit coverage? Roadmap requiring changes?
  • Governance model: single key, multisig, DAO voting?

Core Principles

  • Immutability maximizes trust but freezes bug fixes; upgradeability enables fixes but requires governance and transparency.
  • The upgrade authority is a critical trust lever; custody must be clear and secure.
  • Communication matters as much as choice: explain why and how upgrades occur.

Workflow

  1. Map risks and needs

- Identify required future changes (features, bug fixes) and severity of potential bugs.

  1. Choose model

- If stable and simple -> consider immutability. - If evolving or complex -> keep upgradeable under multisig/DAO with policies.

  1. Governance setup

- If upgradeable: configure multisig thresholds, access control, time-locks if available; document process.

  1. Communication

- Publish program id, authority holder, policy (when upgrades happen, notice window, how to verify binaries/IDL).

  1. Execution

- Rotate authority to final holder or set to BPFLoaderUpgradeab1e none for immutable; record tx.

  1. Verification

- Post-upgrade: verify program data hash, slot, authority state; update registry and README.

Templates / Playbooks

  • Decision table: need for future change? audit status? user trust requirement? -> recommendation.
  • Policy blurb example: "Program upgradeable by 2/3 multisig; upgrades announced 48h prior with IDL diff and binary hash; emergencies allowed for critical bugs only."

Common Failure Modes + Debugging

  • Forgetting to rotate upgrade authority post-launch -> centralization FUD.
  • Losing upgrade key -> inability to fix critical bugs.
  • Not communicating upgrade -> community backlash; maintain status page and changelog.

Quality Bar / Validation

  • Clear recorded choice with txid; authority custody documented.
  • Policy published and consistent across channels.
  • Post-action verification of program authority state.

Output Format

Provide decision summary, rationale, authority state, policy text, and verification commands/txids.

Examples

  • Simple: Small utility program, audited, fixed scope -> set immutable; publish tx and hash.
  • Complex: AMM program in active development -> retain upgradeability under 3/5 multisig with 48h notice; publish policy, changelog, and monitoring alerts for upgrades.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenCode

26.18%
按下载量换算18

Claude Code

25.63%
按下载量换算18

Cursor

20.56%
按下载量换算14

Codex

12.95%
按下载量换算9

Antigravity

9.01%
按下载量换算6

Gemini CLI

3.65%
按下载量换算3

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

权限需确认

当前来源未能明确判断权限范围,默认进入异常复核队列。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。

来源信息

继续浏览同类 Skills