skills/felipeangeli/skills/golang-pro/Gen Agent Trust Hub

golang-pro

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [METADATA_POISONING]: The author URL in the skill metadata refers to a different GitHub user than the provided author context, though this appears to be an artifact of skill reuse rather than a malicious deception.\n
  • Evidence: YAML frontmatter 'author' field is 'https://github.com/Jeffallan' while the provided context is 'felipeangeli'.\n- [COMMAND_EXECUTION]: The skill instructions specify the execution of shell commands for code validation and testing within the local environment.\n
  • Evidence: Instructions to run 'go vet ./...', 'golangci-lint run', and 'go test -race' in SKILL.md.\n
  • Context: These are standard development operations for the Go language ecosystem.\n- [EXTERNAL_DOWNLOADS]: The reference materials describe procedures for downloading and installing Go packages and developer tools from official registries and public repositories.\n
  • Evidence: Examples using 'go mod download' and 'go install' targeting public repositories in 'references/project-structure.md'.\n
  • Context: These operations target well-known package registries and repositories such as GitHub and golang.org.\n- [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided Go source code and maintains the capability to trigger shell commands, which presents a surface for potential indirect prompt injection.\n
  • Ingestion points: The skill analyzes Go source code files provided by the user in the conversation context.\n
  • Boundary markers: The skill does not define specific delimiters or security instructions to isolate untrusted input code.\n
  • Capability inventory: The agent is instructed to invoke the shell for linting, testing, and building as part of the primary workflow.\n
  • Sanitization: No specific sanitization logic is provided for the code inputs before they are processed by the Go toolchain.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — golang-pro