go-workspace-skill
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes a workspace configuration file (
.go-workspace.json) which acts as an untrusted input surface. - Ingestion points: The
load_reposfunction inscripts/workspace.pyreads and parses the JSON configuration file from the workspace root or an environment variable. - Boundary markers: There are no markers or validation steps to distinguish between legitimate repository configurations and malicious ones.
- Capability inventory: The skill can execute shell commands (
git,go), write configuration files, and recursively delete directories (shutil.rmtree). - Sanitization: The skill lacks sanitization for the
namefield in the repository configuration, allowing for path traversal attacks. - [COMMAND_EXECUTION]: The skill uses
subprocess.runto executegitandgocommands using data supplied in the configuration file. - The
repo.namefield is joined with the workspace root without validation:repo_dir = root / repo.name. - A malicious configuration can use parent directory references (e.g.,
../../) or absolute paths in thenamefield to target files outside the intended workspace root. - The
clean --forcecommand usesshutil.rmtreeon these paths, which could lead to unauthorized deletion of sensitive user data if a malicious configuration is loaded. - [REMOTE_CODE_EXECUTION]: The skill clones code from external URLs and executes it locally.
- The
synccommand downloads code from URLs specified in the config. - The
buildandtestcommands rungo build ./...andgo test ./...inside these directories. If a configuration points to a malicious repository, building or testing it can trigger the execution of arbitrary code via Go's build system or test runners. - [EXTERNAL_DOWNLOADS]: The skill performs network operations using
git cloneto fetch repositories from URLs provided in the.go-workspace.jsonfile.
Audit Metadata