golang-documentation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data by instructing the agent to read and process source code and documentation files across the project. This creates a surface where malicious instructions hidden in comments or strings within the scanned codebase could potentially influence the agent's behavior during documentation generation or review.
  • Ingestion points: The skill operates on all .go files and project documentation files like README.md and CHANGELOG.md.
  • Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore' instructions for the data it ingests from source files.
  • Capability inventory: The skill has access to Read, Write, Edit, Bash, Agent, and WebFetch tools, which could be leveraged if an injection is successful.
  • Sanitization: No specific sanitization logic for ingested code content is described in the prompt.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool restricted to go, git, and golangci-lint commands. These are utilized for legitimate development workflows, such as generating documentation (go doc) or linting project files. The restricted scope follows security best practices.
  • [EXTERNAL_DOWNLOADS]: The documentation templates and guides recommend using well-known external tools such as swaggo/swag and buf for API documentation and linting. These are established services in the Golang community and are referenced for standard documentation and development tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:24 PM
Security Audit — agent-trust-hub — golang-documentation