golang-dependency-injection

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's 'Refactor mode' and 'Orchestration mode' analyze a user's codebase to identify architectural patterns and propose migration plans. This process involves ingesting untrusted data (the local code) which is then used to drive high-capability tools including file modification and shell execution. Malicious instructions embedded in code comments or strings within the analyzed codebase could potentially influence the agent's refactoring output. * Ingestion points: Local source code files during refactoring analysis (SKILL.md). * Boundary markers: Absent; instructions do not specify delimiters to separate code content from directives. * Capability inventory: File system modification (Write, Edit), terminal access (Bash), and web fetching (WebFetch). * Sanitization: Absent; no explicit validation or filtering of ingested code content is described before processing.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and repositories for established Go libraries including Google Wire, Uber-Go Dig/Fx, and samber/do. These are well-known technology organizations and the references are used for providing technical guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 07:03 AM
Security Audit — agent-trust-hub — golang-dependency-injection