golang-binary-size-reduction
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements a set of well-defined, safe practices for Go binary optimization. It explicitly forbids dangerous compiler flags, such as
-gcflags=all=-B(which disables bounds checks), and provides clear warnings against techniques that could break runtime behavior or security, such as applying UPX compression to macOS binaries. - [INDIRECT_PROMPT_INJECTION]: The skill contains an inherent surface for indirect prompt injection because its primary function is to audit Go projects by reading potentially untrusted project files, such as
Makefile,Dockerfile, andgoreleaser.yaml, to identify build tags and optimization opportunities. - Ingestion points: The instructions in
SKILL.mdandreferences/workflow.mddirect the agent to parse build configurations and source code for feature-gating tags. - Capability inventory: The skill utilizes shell scripts that perform subprocess calls (
go build,go list,grep) and file system operations, providing the agent with scoped system interaction capabilities. - Boundary markers: The instructions do not define explicit boundary markers or "ignore" directives for the content parsed from these external project files.
- Sanitization: The provided shell scripts use secure coding practices, such as bash arrays for command arguments, which helps prevent shell injection from untrusted metadata found in project files.
Audit Metadata