golang-documentation

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to read and process project source code (**/*.go) for documentation purposes without explicit instructions to sanitize or ignore instructions embedded in code comments.
  • Ingestion points: Source code files (**/*.go).
  • Boundary markers: Absent.
  • Capability inventory: File write/edit and shell execution (restricted Bash).
  • Sanitization: Absent.
  • [DATA_EXFILTRATION]: The skill recommends registering project information with external third-party services (context7.com, deepwiki.com, opendeep.wiki, and zread.ai) for discoverability purposes, which involves sharing project details with non-official domains.
  • [EXTERNAL_DOWNLOADS]: The documentation includes instructions to download and install various Go tools and binaries from public repositories and official service providers such as GitHub and golang.org.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 07:03 AM
Security Audit — agent-trust-hub — golang-documentation