go-workspace-skills

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/workspace.py script uses the subprocess module to execute system commands including git for repository management and go for building and testing. It also performs destructive file system operations using shutil.rmtree when the clean command is invoked with the --force flag.
  • [EXTERNAL_DOWNLOADS]: The sync command fetches code from remote URLs specified in a .go-workspace.json file found in the workspace root. This allows for the downloading of external code based on the contents of a local configuration file.
  • [REMOTE_CODE_EXECUTION]: The test command invokes go test ./..., which compiles and executes code from the repositories specified in the configuration. This path to execution is an inherent risk of the tool's intended functionality, as it executes code that may have been downloaded from external sources.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it automatically loads configuration from a .go-workspace.json file in the current directory. A malicious repository could include a crafted configuration file that directs the agent to clone malicious code or execute dangerous tests.
  • Ingestion points: The resolve_config_path and load_repos functions in scripts/workspace.py automatically search for and read JSON configuration files from the workspace root.
  • Boundary markers: The skill lacks explicit instructions or delimiters to prevent the agent from following instructions potentially embedded in the repository metadata or configuration files.
  • Capability inventory: The skill has the capability to execute shell commands (git, go), write files (init-config), and delete directories (clean).
  • Sanitization: While the script validates that repository names match the configuration, it does not perform deep validation of the repository URLs or the contents of the repositories before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 10:34 AM
Security Audit — agent-trust-hub — go-workspace-skills