go-workspace-skill

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes a workspace configuration file (.go-workspace.json) which acts as an untrusted input surface.
  • Ingestion points: The load_repos function in scripts/workspace.py reads and parses the JSON configuration file from the workspace root or an environment variable.
  • Boundary markers: There are no markers or validation steps to distinguish between legitimate repository configurations and malicious ones.
  • Capability inventory: The skill can execute shell commands (git, go), write configuration files, and recursively delete directories (shutil.rmtree).
  • Sanitization: The skill lacks sanitization for the name field in the repository configuration, allowing for path traversal attacks.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute git and go commands using data supplied in the configuration file.
  • The repo.name field is joined with the workspace root without validation: repo_dir = root / repo.name.
  • A malicious configuration can use parent directory references (e.g., ../../) or absolute paths in the name field to target files outside the intended workspace root.
  • The clean --force command uses shutil.rmtree on these paths, which could lead to unauthorized deletion of sensitive user data if a malicious configuration is loaded.
  • [REMOTE_CODE_EXECUTION]: The skill clones code from external URLs and executes it locally.
  • The sync command downloads code from URLs specified in the config.
  • The build and test commands run go build ./... and go test ./... inside these directories. If a configuration points to a malicious repository, building or testing it can trigger the execution of arbitrary code via Go's build system or test runners.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations using git clone to fetch repositories from URLs provided in the .go-workspace.json file.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 10:09 AM
Security Audit — agent-trust-hub — go-workspace-skill