golang-error-handling

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and audit untrusted Go source code across a codebase. Maliciously crafted content within the analyzed files (such as instructions hidden in comments or string literals) could attempt to influence the agent's behavior.
  • Ingestion points: All Go source files targeted by the skill's file pattern (**/*.go).
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" markers for the source code content being analyzed.
  • Capability inventory: The skill configuration allows access to file operations (Read, Edit, Write) and shell commands (Bash(go:*), Bash(git:*), Bash(golangci-lint:*)), which provides a significant capability set if an injection were successful.
  • Sanitization: The prompt does not specify sanitization or validation logic for the external code data processed during audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:55 AM
Security Audit — agent-trust-hub — golang-error-handling