go
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to read and analyze source files from external Go dependencies, creating a surface for instructions embedded in third-party code.\n
- Ingestion points: Dependency source files accessed via the path provided by
go mod download.\n - Boundary markers: Absent; the agent reads raw source code files.\n
- Capability inventory: The skill allows execution of Go code via
go runand file reading.\n - Sanitization: No specific filtering or sanitization of external source code is defined.\n- [EXTERNAL_DOWNLOADS]: The skill uses
go mod downloadto fetch project dependencies from official or community registries.\n - Evidence: Instructions to use
go mod download -json MODULEto obtain source files.\n- [COMMAND_EXECUTION]: The skill includes instructions to execute Go programs directly from the shell.\n - Evidence: Use of
go run .andgo run ./cmd/footo execute Go packages.
Audit Metadata