go-testing-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues or malicious patterns were identified. The skill's instructions and references align with established software testing best practices. The examples provided for table-driven tests, HTTP mocking, and filesystem testing using t.TempDir are standard Go testing patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection as it is designed to process untrusted source code and configuration files. However, the risk is minimal given the skill's intended purpose and lack of dangerous capabilities.
  • Ingestion points: Go source code files (*_test.go) and module configuration files (go.mod) are read and analyzed as part of the review process.
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore" warnings to distinguish between the code being reviewed and the agent's instructions.
  • Capability inventory: The skill is limited to reading files and providing textual feedback; it does not request tool permissions for network exfiltration, arbitrary command execution, or persistent filesystem modifications.
  • Sanitization: The instructions do not define sanitization or escaping protocols for the ingested source code data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:32 PM
Security Audit — agent-trust-hub — go-testing-code-review