golang-benchmark

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external benchmark results from files such as bench.txt, old.txt, and new.txt. These results are ingested into the agent context for analysis using benchstat. This represents a potential indirect prompt injection surface where maliciously formatted benchmark output could attempt to influence the agent's interpretation. * Ingestion points: Benchmark output files read in SKILL.md and references/benchstat.md. * Boundary markers: None specified. * Capability inventory: Includes Bash, Read, Write, and Edit across scripts. * Sanitization: No explicit sanitization of benchmark content is defined.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of several community and official tools via go install. These include the official benchstat tool and community tools such as benchdiff, cob, and gobenchdata, as well as the fgprof profiler. * Evidence: go install commands found in SKILL.md, references/benchstat.md, references/ci-regression.md, and references/tools.md.\n- [PRIVILEGE_ESCALATION]: The CI regression reference file provides instructions for system-level tuning on dedicated runners, which involves executing sudo commands to modify CPU frequency scaling, Turbo Boost, and SMT settings. While documented with strong warnings for use only on dedicated hardware, these remain high-privilege operations. * Evidence: sudo tee commands in references/ci-regression.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:38 PM
Security Audit — agent-trust-hub — golang-benchmark