golang-database

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill promotes security best practices, such as mandatory parameterized queries to prevent SQL injection and the propagation of context to manage query lifecycles and cancellations.
  • [SAFE]: External dependencies and tools referenced, such as sqlx, pgx, golang-migrate, Flyway, Atlas, and testcontainers-go, are well-known, established libraries and services within the Go ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface where the agent processes user-provided Go source files which could contain instructions intended to influence behavior.
  • Ingestion points: Reads project Go files (**/*.go) using Read, Glob, and Grep tools.
  • Boundary markers: None explicitly defined for delimiting code content from instructions.
  • Capability inventory: Includes file system modification (Edit, Write) and shell command execution (go, git, golangci-lint).
  • Sanitization: The skill instructs the agent to enforce input sanitization in the application code it generates, though it does not specify sanitization for its own ingestion of code comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:39 PM
Security Audit — agent-trust-hub — golang-database