go-workspace-skills
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/workspace.pyscript uses thesubprocessmodule to execute system commands includinggitfor repository management andgofor building and testing. It also performs destructive file system operations usingshutil.rmtreewhen thecleancommand is invoked with the--forceflag. - [EXTERNAL_DOWNLOADS]: The
synccommand fetches code from remote URLs specified in a.go-workspace.jsonfile found in the workspace root. This allows for the downloading of external code based on the contents of a local configuration file. - [REMOTE_CODE_EXECUTION]: The
testcommand invokesgo test ./..., which compiles and executes code from the repositories specified in the configuration. This path to execution is an inherent risk of the tool's intended functionality, as it executes code that may have been downloaded from external sources. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it automatically loads configuration from a
.go-workspace.jsonfile in the current directory. A malicious repository could include a crafted configuration file that directs the agent to clone malicious code or execute dangerous tests. - Ingestion points: The
resolve_config_pathandload_reposfunctions inscripts/workspace.pyautomatically search for and read JSON configuration files from the workspace root. - Boundary markers: The skill lacks explicit instructions or delimiters to prevent the agent from following instructions potentially embedded in the repository metadata or configuration files.
- Capability inventory: The skill has the capability to execute shell commands (
git,go), write files (init-config), and delete directories (clean). - Sanitization: While the script validates that repository names match the configuration, it does not perform deep validation of the repository URLs or the contents of the repositories before execution.
Audit Metadata