golang-dependency-management
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes dependency definitions and configuration files (go.mod, go.sum) which are potentially untrusted ingestion points.
- Ingestion points: Processes existing go.mod and go.sum files within the project directory to identify dependencies.
- Boundary markers: Explicitly mandates that the agent must ask the user for confirmation before running go get to add any new dependency.
- Capability inventory: Utilizes Bash for go, git, and govulncheck commands, and has Read, Write, and Edit permissions for project files.
- Sanitization: Relies on the built-in integrity checking of the Go toolchain (checksum verification) and manual user oversight for new dependency additions.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading and installing various command-line tools from external repositories.
- Evidence: Facilitates installation of govulncheck from golang.org/x/vuln/cmd/govulncheck, golangci-lint from github.com/golangci/golangci-lint, and other analysis tools like go-mod-outdated and goweight from GitHub.
- [COMMAND_EXECUTION]: The skill enables the execution of the Go toolchain and related utilities through shell commands.
- Evidence: Performs operations such as go get, go mod tidy, go mod verify, and go tool to manage the module lifecycle and perform security audits.
Audit Metadata