go

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external Go project files, which constitutes an attack surface where malicious instructions could be embedded in processed data.
  • Ingestion points: Processes Go source code (.go), module files (go.mod), and checksums (go.sum) as defined in the auto-detect rules.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands in target files.
  • Capability inventory: The verification checklist suggests executing shell-based tools like go build, go test, and golangci-lint on the processed files.
  • Sanitization: There are no provisions for sanitizing or escaping content from Go files before processing or tool execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — go