golang-concurrency
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection through its interaction with project source code.
- Ingestion points: The
pathsconfiguration inSKILL.mdallows the agent to ingest all**/*.gofiles within a project directory. Maliciously crafted content within these files (such as comments or string literals) could potentially influence the agent's behavior. - Boundary markers: Absent. There are no instructions in
SKILL.mddefining specific delimiters or warning markers to help the agent distinguish between static code data and its own control instructions. - Capability inventory: According to the
allowed-toolsinSKILL.md, the agent hasWriteandEditpermissions, and can executeBashcommands (specificallygo,golangci-lint, andgit). These capabilities could be misused if an injection successfully subverts the agent's instructions. - Sanitization: Absent. The skill does not provide guidelines for sanitizing, validating, or escaping data retrieved from the codebase before it is integrated into the agent's reasoning or output.
Audit Metadata