golang-dependency-injection
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's 'Refactor mode' and 'Orchestration mode' analyze a user's codebase to identify architectural patterns and propose migration plans. This process involves ingesting untrusted data (the local code) which is then used to drive high-capability tools including file modification and shell execution. Malicious instructions embedded in code comments or strings within the analyzed codebase could potentially influence the agent's refactoring output. * Ingestion points: Local source code files during refactoring analysis (SKILL.md). * Boundary markers: Absent; instructions do not specify delimiters to separate code content from directives. * Capability inventory: File system modification (Write, Edit), terminal access (Bash), and web fetching (WebFetch). * Sanitization: Absent; no explicit validation or filtering of ingested code content is described before processing.
- [EXTERNAL_DOWNLOADS]: The skill references documentation and repositories for established Go libraries including Google Wire, Uber-Go Dig/Fx, and samber/do. These are well-known technology organizations and the references are used for providing technical guidance.
Audit Metadata