golang-concurrency

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection through its interaction with project source code.
  • Ingestion points: The paths configuration in SKILL.md allows the agent to ingest all **/*.go files within a project directory. Maliciously crafted content within these files (such as comments or string literals) could potentially influence the agent's behavior.
  • Boundary markers: Absent. There are no instructions in SKILL.md defining specific delimiters or warning markers to help the agent distinguish between static code data and its own control instructions.
  • Capability inventory: According to the allowed-tools in SKILL.md, the agent has Write and Edit permissions, and can execute Bash commands (specifically go, golangci-lint, and git). These capabilities could be misused if an injection successfully subverts the agent's instructions.
  • Sanitization: Absent. The skill does not provide guidelines for sanitizing, validating, or escaping data retrieved from the codebase before it is integrated into the agent's reasoning or output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:41 AM
Security Audit — agent-trust-hub — golang-concurrency