skills/ericrisco/rsc-harness/go/Gen Agent Trust Hub

go

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/verify.sh script facilitates quality checks using standard Go tools such as go fmt, go vet, and go test, alongside common community linters like staticcheck and golangci-lint. These tools are executed locally to validate code integrity.
  • [EXTERNAL_DOWNLOADS]: The skill references standard Go libraries and utilities from well-known, trusted sources including golang.org, honnef.co, and official GitHub repositories. These are standard dependencies within the Go ecosystem and do not represent a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes user-provided Go source code, which serves as a potential vector for indirect prompt injection. Evidence: 1. Ingestion points: User-supplied Go files in the agent's workspace. 2. Boundary markers: Not explicitly defined within the skill's instruction set. 3. Capability inventory: Local shell command execution for code validation and testing via the provided script. 4. Sanitization: The skill recommends security-positive practices including govulncheck for vulnerability detection and strict SQL parametrization.
  • [SAFE]: The skill content is legitimate and adheres to secure development practices. No evidence of malicious prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — go