code-review-go

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a purely instructional reference guide for auditing Go source code. It does not contain any executable scripts, network operations, or file system modifications.
  • [METADATA_POISONING]: The YAML frontmatter metadata correctly describes the skill's purpose as a security reference for Go code. No deceptive instructions or malicious patterns were found in the metadata fields.
  • [COMMAND_EXECUTION]: While the skill mentions command execution sinks like exec.Command, it does so in the context of identifying vulnerabilities within the code being reviewed. The skill itself does not execute any commands.
  • [INDIRECT_PROMPT_INJECTION]: Although the skill is designed to analyze potentially untrusted Go source code, it acts as a set of static guidelines for the agent. It does not perform dynamic data ingestion or interpolation that could be exploited to bypass agent safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — code-review-go