golang-google-wire
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of development tools from a trusted organization. Specifically, it suggests using
go install github.com/google/wire/cmd/wire@latestto obtain the necessary CLI. - [COMMAND_EXECUTION]: The skill uses shell commands to manage the application's dependency graph. Key commands include
wire ./...for code generation andwire check ./...for graph validation. Access is limited through theallowed-toolsfrontmatter configuration. - [DYNAMIC_EXECUTION]: The skill facilitates the generation of Go source code (
wire_gen.go) at build time. This code is intended to be committed to the repository and compiled into the final binary, which is a standard pattern for compile-time dependency injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes local project files which serves as a potential vector for indirect prompt injection if the codebase originates from an untrusted source.
- Ingestion points: Processes
**/*.gosource files through thewireCLI andgoplsLSP integration. - Boundary markers: No explicit instructions are provided to the agent to distinguish between code-level instructions and data.
- Capability inventory: The skill is granted
Bash,Read,Write, andEditcapabilities as defined in the skill configuration. - Sanitization: The skill relies on the standard Go compiler and the
google/wireparser to handle file contents.
Audit Metadata