golang-documentation
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to read and process project source code (**/*.go) for documentation purposes without explicit instructions to sanitize or ignore instructions embedded in code comments.
- Ingestion points: Source code files (**/*.go).
- Boundary markers: Absent.
- Capability inventory: File write/edit and shell execution (restricted Bash).
- Sanitization: Absent.
- [DATA_EXFILTRATION]: The skill recommends registering project information with external third-party services (context7.com, deepwiki.com, opendeep.wiki, and zread.ai) for discoverability purposes, which involves sharing project details with non-official domains.
- [EXTERNAL_DOWNLOADS]: The documentation includes instructions to download and install various Go tools and binaries from public repositories and official service providers such as GitHub and golang.org.
Audit Metadata