# Pitfall Log / 踩坑日志

项目：Emasoft/claude-plugins-validation

摘要：发现 40 个潜在踩坑项，其中 4 个为 high/blocking；最高优先级：安全/权限坑 - 失败模式：security_permissions: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-...。

## 1. 安全/权限坑 · 失败模式：security_permissions: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-...

- 严重度：high
- 证据强度：source_linked
- 发现：Developers should check this security_permissions risk before relying on the project: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
- 对用户的影响：Developers may expose sensitive permissions or credentials: Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/169 | Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)

## 2. 安全/权限坑 · 失败模式：security_permissions: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note descrip...

- 严重度：high
- 证据强度：source_linked
- 发现：Developers should check this security_permissions risk before relying on the project: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)
- 对用户的影响：Developers may expose sensitive permissions or credentials: skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/178 | skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)

## 3. 安全/权限坑 · 失败模式：security_permissions: standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed on...

- 严重度：high
- 证据强度：source_linked
- 发现：Developers should check this security_permissions risk before relying on the project: standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version} resolver tag
- 对用户的影响：Developers may expose sensitive permissions or credentials: standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version} resolver tag
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/165 | standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version} resolver tag

## 4. 安全/权限坑 · 来源证据：Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release s…

- 严重度：high
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/180 | 来源讨论提到 macos 相关条件，需在安装/试用前复核。

## 5. 安装坑 · 失败模式：installation: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this installation risk before relying on the project: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets
- 对用户的影响：Developers may fail before the first successful local run: Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/180 | Canonical-pipeline validate step hangs ~30 min AFTER CPV builds (4s) — not #114's cold-build cause; timed-out release shipped with no assets

## 6. 安装坑 · 失败模式：installation: Scan dependencies (not just the plugin tree) for agent-context writers, and score capability...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this installation risk before relying on the project: Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately
- 对用户的影响：Developers may fail before the first successful local run: Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/174 | Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately

## 7. 安装坑 · 失败模式：installation: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this installation risk before relying on the project: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)
- 对用户的影响：Developers may fail before the first successful local run: feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/175 | feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)

## 8. 安装坑 · 失败模式：installation: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zs...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this installation risk before relying on the project: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)
- 对用户的影响：Developers may fail before the first successful local run: skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/177 | skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)

## 9. 安装坑 · 失败模式：installation: v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex mis...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this installation risk before relying on the project: v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex misses the two-call push shape); residual signal is a non-blocking WARNING; its remedia...
- 对用户的影响：Developers may fail before the first successful local run: v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex misses the two-call push shape); residual signal is a non-blocking WARNING; its remedia...
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/167 | v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex misses the two-call push shape); residual signal is a non-blocking WARNING; its remedia...

## 10. 配置坑 · 可能修改宿主 AI 配置

- 严重度：medium
- 证据强度：source_linked
- 发现：项目面向 Claude/Cursor/Codex/Gemini/OpenCode 等宿主，或安装命令涉及用户配置目录。
- 对用户的影响：安装可能改变本机 AI 工具行为，用户需要知道写入位置和回滚方法。
- 证据：capability.host_targets | https://github.com/Emasoft/claude-plugins-validation | host_targets=mcp_host, claude_code, claude

## 11. 配置坑 · 失败模式：configuration: CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED, and plugin o...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED, and plugin options are no longer read from project settings.json — CPV has no rule for either
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED, and plugin options are no longer read from project settings.json — CPV has no rule for either
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/166 | CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED, and plugin options are no longer read from project settings.json — CPV has no rule for either

## 12. 配置坑 · 失败模式：configuration: RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the litera...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the literal never appears in publish.py
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the literal never appears in publish.py
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/168 | RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the literal never appears in publish.py

## 13. 配置坑 · 失败模式：configuration: Recognize CC v2.1.218 skill-frontmatter field 'background' (currently flagged 'Unknown frontm...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: Recognize CC v2.1.218 skill-frontmatter field 'background' (currently flagged 'Unknown frontmatter field')
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: Recognize CC v2.1.218 skill-frontmatter field 'background' (currently flagged 'Unknown frontmatter field')
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/173 | Recognize CC v2.1.218 skill-frontmatter field 'background' (currently flagged 'Unknown frontmatter field')

## 14. 配置坑 · 失败模式：configuration: bug(--strict scope): validates non-shippable tracked content (project-memory, test fixtures)...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: bug(--strict scope): validates non-shippable tracked content (project-memory, test fixtures) + gitignored files
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: bug(--strict scope): validates non-shippable tracked content (project-memory, test fixtures) + gitignored files
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/176 | bug(--strict scope): validates non-shippable tracked content (project-memory, test fixtures) + gitignored files

## 15. 配置坑 · 失败模式：configuration: canonical publish.py: run() hardcodes timeout=300, making the test gate unsatisfiable for a r...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: canonical publish.py: run() hardcodes timeout=300, making the test gate unsatisfiable for a real suite
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: canonical publish.py: run() hardcodes timeout=300, making the test gate unsatisfiable for a real suite
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/179 | canonical publish.py: run() hardcodes timeout=300, making the test gate unsatisfiable for a real suite

## 16. 配置坑 · 失败模式：configuration: cpv_validation_common.py trips bandit B108 on its own data constants — blocks publish.py --ga...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: cpv_validation_common.py trips bandit B108 on its own data constants — blocks publish.py --gate for every plugin vendoring it
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: cpv_validation_common.py trips bandit B108 on its own data constants — blocks publish.py --gate for every plugin vendoring it
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/172 | cpv_validation_common.py trips bandit B108 on its own data constants — blocks publish.py --gate for every plugin vendoring it

## 17. 配置坑 · 失败模式：configuration: skillaudit: defensive anti-injection guardrails flagged as injection (4 detectors, NIT blocks...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: skillaudit: defensive anti-injection guardrails flagged as injection (4 detectors, NIT blocks --strict); retro-breaks green releases
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: skillaudit: defensive anti-injection guardrails flagged as injection (4 detectors, NIT blocks --strict); retro-breaks green releases
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/170 | skillaudit: defensive anti-injection guardrails flagged as injection (4 detectors, NIT blocks --strict); retro-breaks green releases

## 18. 配置坑 · 失败模式：configuration: standardize --fix generates a .cspell.json that trips CPV's own skillaudit TOOL_SHADOW detect...

- 严重度：medium
- 证据强度：source_linked
- 发现：Developers should check this configuration risk before relying on the project: standardize --fix generates a .cspell.json that trips CPV's own skillaudit TOOL_SHADOW detector (clean repo -> blocking MAJOR)
- 对用户的影响：Developers may misconfigure credentials, environment, or host setup: standardize --fix generates a .cspell.json that trips CPV's own skillaudit TOOL_SHADOW detector (clean repo -> blocking MAJOR)
- 证据：failure_mode_cluster:github_issue | https://github.com/Emasoft/claude-plugins-validation/issues/171 | standardize --fix generates a .cspell.json that trips CPV's own skillaudit TOOL_SHADOW detector (clean repo -> blocking MAJOR)

## 19. 能力坑 · 能力判断依赖假设

- 严重度：medium
- 证据强度：source_linked
- 发现：README/documentation is current enough for a first validation pass.
- 对用户的影响：假设不成立时，用户拿不到承诺的能力。
- 证据：capability.assumptions | https://github.com/Emasoft/claude-plugins-validation | README/documentation is current enough for a first validation pass.

## 20. 维护坑 · 维护活跃度未知

- 严重度：medium
- 证据强度：source_linked
- 发现：未记录 last_activity_observed。
- 对用户的影响：新项目、停更项目和活跃项目会被混在一起，推荐信任度下降。
- 证据：evidence.maintainer_signals | https://github.com/Emasoft/claude-plugins-validation | last_activity_observed missing

- 严重度：medium
- 证据强度：source_linked
- 发现：no_demo
- 证据：downstream_validation.risk_items | https://github.com/Emasoft/claude-plugins-validation | no_demo; severity=medium

## 22. 安全/权限坑 · 存在安全注意事项

- 严重度：medium
- 证据强度：source_linked
- 发现：No sandbox install has been executed yet; downstream must verify before user use.
- 对用户的影响：用户安装前需要知道权限边界和敏感操作。
- 证据：risks.safety_notes | https://github.com/Emasoft/claude-plugins-validation | No sandbox install has been executed yet; downstream must verify before user use.

## 23. 安全/权限坑 · 存在评分风险

- 严重度：medium
- 证据强度：source_linked
- 发现：no_demo
- 对用户的影响：风险会影响是否适合普通用户安装。
- 证据：risks.scoring_risks | https://github.com/Emasoft/claude-plugins-validation | no_demo; severity=medium

## 24. 安全/权限坑 · 来源证据：CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED, and plugin options are no longer read…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：CC v2.1.207 spec drift: ${user_config.*} in shell-form commands is now REJECTED, and plugin options are no longer read from project settings.json — CPV has no…
- 对用户的影响：可能影响升级、迁移或版本选择。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/166 | 来源类型 github_issue 暴露的待验证使用条件。

## 25. 安全/权限坑 · 来源证据：Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes afte…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：Canonical pre-push hook: strict publish-ancestry gate forbids ALL branch sharing — allow non-default-branch pushes after secret scan (fleet-stall root cause)
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/169 | 来源类型 github_issue 暴露的待验证使用条件。

## 26. 安全/权限坑 · 来源证据：RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the literal never appears in publish…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：RC-DEP-TAG-PIPELINE false-positives on a correct (manifest-derived) resolver tag — the literal never appears in publish.py
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/168 | 来源讨论提到 python 相关条件，需在安装/试用前复核。

## 27. 安全/权限坑 · 来源证据：Recognize CC v2.1.218 skill-frontmatter field 'background' (currently flagged 'Unknown frontmatter field')

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：Recognize CC v2.1.218 skill-frontmatter field 'background' (currently flagged 'Unknown frontmatter field')
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/173 | 来源类型 github_issue 暴露的待验证使用条件。

## 28. 安全/权限坑 · 来源证据：Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：Scan dependencies (not just the plugin tree) for agent-context writers, and score capability vs live separately
- 对用户的影响：可能阻塞安装或首次运行。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/174 | 来源讨论提到 node 相关条件，需在安装/试用前复核。

## 29. 安全/权限坑 · 来源证据：bug(--strict scope): validates non-shippable tracked content (project-memory, test fixtures) + gitignored files

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：bug(--strict scope): validates non-shippable tracked content (project-memory, test fixtures) + gitignored files
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/176 | 来源类型 github_issue 暴露的待验证使用条件。

## 30. 安全/权限坑 · 来源证据：canonical publish.py: run() hardcodes timeout=300, making the test gate unsatisfiable for a real suite

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：canonical publish.py: run() hardcodes timeout=300, making the test gate unsatisfiable for a real suite
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/179 | 来源类型 github_issue 暴露的待验证使用条件。

## 31. 安全/权限坑 · 来源证据：cpv_validation_common.py trips bandit B108 on its own data constants — blocks publish.py --gate for every plugin vendor…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：cpv_validation_common.py trips bandit B108 on its own data constants — blocks publish.py --gate for every plugin vendoring it
- 对用户的影响：可能阻塞安装或首次运行。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/172 | 来源讨论提到 python 相关条件，需在安装/试用前复核。

## 32. 安全/权限坑 · 来源证据：feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：feat(canonical-pipeline): gate Rust + shell when a plugin ships them (regen drops them silently)
- 对用户的影响：可能阻塞安装或首次运行。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/175 | 来源讨论提到 python 相关条件，需在安装/试用前复核。

## 33. 安全/权限坑 · 来源证据：skillaudit: defensive anti-injection guardrails flagged as injection (4 detectors, NIT blocks --strict); retro-breaks g…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：skillaudit: defensive anti-injection guardrails flagged as injection (4 detectors, NIT blocks --strict); retro-breaks green releases
- 对用户的影响：可能阻塞安装或首次运行。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/170 | 来源类型 github_issue 暴露的待验证使用条件。

## 34. 安全/权限坑 · 来源证据：skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：skillaudit:agent_manipulation MCP_SCHEMA_POISON false-positive on wikimem memory-note description: PROSE (same class as #177 / #156)
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/178 | 来源类型 github_issue 暴露的待验证使用条件。

## 35. 安全/权限坑 · 来源证据：skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：skillaudit:filesystem FS_WRITE false-positive on install-doc PROSE (bash comment naming ~/.zshrc)
- 对用户的影响：可能阻塞安装或首次运行。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/177 | 来源类型 github_issue 暴露的待验证使用条件。

## 36. 安全/权限坑 · 来源证据：standardize --fix generates a .cspell.json that trips CPV's own skillaudit TOOL_SHADOW detector (clean repo -> blocking…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：standardize --fix generates a .cspell.json that trips CPV's own skillaudit TOOL_SHADOW detector (clean repo -> blocking MAJOR)
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/171 | 来源讨论提到 python 相关条件，需在安装/试用前复核。

## 37. 安全/权限坑 · 来源证据：standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publis…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：standardize still strips documented linter suppressions (MD010, CKV_DOCKER_2) — #145 fixed only MD025; and canon publish.py never creates the {name}--v{version…
- 对用户的影响：可能影响授权、密钥配置或安全边界。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/165 | 来源讨论提到 docker 相关条件，需在安装/试用前复核。

## 38. 安全/权限坑 · 来源证据：v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex misses the two-call push shap…

- 严重度：medium
- 证据强度：source_linked
- 发现：GitHub 社区证据显示该项目存在一个安全/权限相关的待验证问题：v2.158.0: the #165 resolver-tag migration SILENTLY skips 6/13 fleet plugins (anchor regex misses the two-call push shape); residual signal is a non-blocking WA…
- 对用户的影响：可能影响升级、迁移或版本选择。
- 证据：community_evidence:github | https://github.com/Emasoft/claude-plugins-validation/issues/167 | 来源讨论提到 python 相关条件，需在安装/试用前复核。

## 39. 维护坑 · issue/PR 响应质量未知

- 严重度：low
- 证据强度：source_linked
- 发现：issue_or_pr_quality=unknown。
- 对用户的影响：用户无法判断遇到问题后是否有人维护。
- 证据：evidence.maintainer_signals | https://github.com/Emasoft/claude-plugins-validation | issue_or_pr_quality=unknown

## 40. 维护坑 · 发布节奏不明确

- 严重度：low
- 证据强度：source_linked
- 发现：release_recency=unknown。
- 对用户的影响：安装命令和文档可能落后于代码，用户踩坑概率升高。
- 证据：evidence.maintainer_signals | https://github.com/Emasoft/claude-plugins-validation | release_recency=unknown
