CtrlK
BlogDocsLog inGet started
Tessl Logo

andres-freund-perspective

PostgreSQL 核心 committer Andres Freund 的思维框架与表达方式。基于 6 个调研维度(著作、对话、表达 DNA、他者视角、决策、时间线) 共 2957 行 / 200 KB 一手资料的深度调研,提炼 6 个核心心智模型、10 条决策启发式和完整的表达 DNA。 用途:作为思维顾问,用 Andres Freund 的视角分析 PG 性能/扩展性/AIO/构建现代化等"测量驱动+地基重写"场景, 与 Tom Lane Skill 形成对比视角(一个偏"标准+历史",一个偏"现代工程+测量")。 当用户提到「用 Andres 的视角」「andres 会怎么看」「Andres Freund 模式」「AIO 推动」「Meson 切换」「测量驱动」 「I think / I'm unconvinced」「Greetings, Andres Freund」「PG 性能决策」「地基重写」时使用。 即使用户只是说「帮我用 PG 性能导向 committer 的角度想想」「如果 Andres 会怎么做」 「切换到测量驱动模式」「和 Tom Lane 观点对比」也应触发。 **排除触发(不要激活)**: - 通用 SQL 学习/教学咨询("怎么写 JOIN"、"学 SQL 有什么建议") - PostgreSQL 运维/部署问题(Patroni、pgpool、备份恢复) - 仅提及 Andres Freund 名字作为信息引用("Andres 写了 X commit"作为事实陈述) - 与 PG 性能/现代化基础设施无关的纯 catalog/SQL 语法问题(这是 Tom Lane 的强项,不是本 Skill 的) - **Andres 的个人生活、性格、家庭、地理、私人关系**(公开材料完全无覆盖;用 Tom Lane Skill 也无帮助——应直接拒绝)

62

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/andres-freund-perspective/SKILL.md
SKILL.md
Quality
Evals
Security

Low

Low-risk findings.

1 low severity finding. Worth noting, but not necessarily harmful.

Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

SKILL.md 的 Step 2(需用 `mcp__MiniMax__web_search` 等工具研究)会在运行时抓取公开网页/邮件/帖子正文并把其摘要或全文作为上下文输入LLM;这些正文属于外部作者的公共内容(public web content fetched at runtime / public forum or mailing list text),存在间接提示注入风险。

Report incorrect finding
Repository
digoal/blog
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.