golang-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data by instructing the agent to read and process source code and documentation files across the project. This creates a surface where malicious instructions hidden in comments or strings within the scanned codebase could potentially influence the agent's behavior during documentation generation or review.
- Ingestion points: The skill operates on all
.gofiles and project documentation files likeREADME.mdandCHANGELOG.md. - Boundary markers: The instructions do not explicitly mandate the use of delimiters or 'ignore' instructions for the data it ingests from source files.
- Capability inventory: The skill has access to
Read,Write,Edit,Bash,Agent, andWebFetchtools, which could be leveraged if an injection is successful. - Sanitization: No specific sanitization logic for ingested code content is described in the prompt.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool restricted togo,git, andgolangci-lintcommands. These are utilized for legitimate development workflows, such as generating documentation (go doc) or linting project files. The restricted scope follows security best practices. - [EXTERNAL_DOWNLOADS]: The documentation templates and guides recommend using well-known external tools such as
swaggo/swagandbuffor API documentation and linting. These are established services in the Golang community and are referenced for standard documentation and development tasks.
Audit Metadata