golang-fullstack-best-practices

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a static knowledge base for performing Go, GORM, and PostgreSQL code reviews. It does not include executable code, scripts, or configurations that would perform network calls, file system modifications, or privileged operations.\n- [PROMPT_INJECTION]: No evidence of malicious prompt injection was found. The instructions are structured to guide the AI agent in identifying specific anti-patterns in user-provided code rather than overriding the agent's core safety protocols.\n- [EXTERNAL_DOWNLOADS]: The skill references several external resources for documentation and community best practices (e.g., gorm.io, postgresql.org, use-the-index-luke.com, refactoring.guru). These are well-known, trusted technology services and documentation sites used for educational context.\n- [REMOTE_CODE_EXECUTION]: There are no patterns of remote code execution. The skill references legitimate third-party libraries and tools (e.g., golang-migrate, goleak, pgx) as industry standards for Go development.\n- [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were detected. Placeholders like 'YOUR_API_KEY_HERE' are used in examples for instruction only and do not constitute a security risk.\n- [DATA_EXFILTRATION]: The skill does not attempt to access or exfiltrate sensitive user data or environment configurations (e.g., .env, .aws, .ssh). Its operations are limited to analyzing the content of provided code files for architectural and logic flaws.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 01:25 PM
Security Audit — agent-trust-hub — golang-fullstack-best-practices