golang-dependency-injection
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a development aid for Go projects, promoting standard software engineering practices like loose coupling and testability. It correctly recommends against global state and service locators, and provides clear templates for integrating trusted DI libraries.
- [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing project source code to map dependencies and suggest refactoring, which creates an inherent surface for indirect prompt injection if analyzed files contain malicious instructions in comments or string literals.
- Ingestion points: The skill reads Go source files (
**/*.go) throughout the project using theReadtool. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded prompts in the analyzed source code.
- Capability inventory: The skill can write or edit files and execute specific development binaries (
go,git,golangci-lint) via theBashtool. - Sanitization: No explicit filtering or sanitization of source code content is specified before processing.
Audit Metadata