go
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external Go project files, which constitutes an attack surface where malicious instructions could be embedded in processed data.
- Ingestion points: Processes Go source code (.go), module files (go.mod), and checksums (go.sum) as defined in the auto-detect rules.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands in target files.
- Capability inventory: The verification checklist suggests executing shell-based tools like go build, go test, and golangci-lint on the processed files.
- Sanitization: There are no provisions for sanitizing or escaping content from Go files before processing or tool execution.
Audit Metadata