golang-performance

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze Go source code (**/*.go) and has access to powerful tools including Bash, Write, and WebFetch. This creates a theoretical surface for indirect prompt injection if the analyzed code contains malicious instructions. However, this is inherent to the skill's primary purpose of code analysis and optimization, and no specific vulnerabilities or bypasses were identified.
  • [REMOTE_CODE_EXECUTION]: The skill uses go install to fetch the benchstat tool from golang.org/x/perf. This is a trusted repository maintained by the official Go project team and does not pose a security risk.
  • [EXTERNAL_DOWNLOADS]: The skill references several external libraries for caching, JSON processing, and observability (e.g., Hashicorp, Elastic, Uber, Prometheus, Grafana). All referenced resources are from well-known technology organizations or the official vendor's own repositories, representing standard development practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 07:03 AM
Security Audit — agent-trust-hub — golang-performance