golang-database
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill promotes security best practices, such as mandatory parameterized queries to prevent SQL injection and the propagation of context to manage query lifecycles and cancellations.
- [SAFE]: External dependencies and tools referenced, such as sqlx, pgx, golang-migrate, Flyway, Atlas, and testcontainers-go, are well-known, established libraries and services within the Go ecosystem.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface where the agent processes user-provided Go source files which could contain instructions intended to influence behavior.
- Ingestion points: Reads project Go files (**/*.go) using Read, Glob, and Grep tools.
- Boundary markers: None explicitly defined for delimiting code content from instructions.
- Capability inventory: Includes file system modification (Edit, Write) and shell command execution (go, git, golangci-lint).
- Sanitization: The skill instructs the agent to enforce input sanitization in the application code it generates, though it does not specify sanitization for its own ingestion of code comments.
Audit Metadata