golang-google-wire

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of development tools from a trusted organization. Specifically, it suggests using go install github.com/google/wire/cmd/wire@latest to obtain the necessary CLI.
  • [COMMAND_EXECUTION]: The skill uses shell commands to manage the application's dependency graph. Key commands include wire ./... for code generation and wire check ./... for graph validation. Access is limited through the allowed-tools frontmatter configuration.
  • [DYNAMIC_EXECUTION]: The skill facilitates the generation of Go source code (wire_gen.go) at build time. This code is intended to be committed to the repository and compiled into the final binary, which is a standard pattern for compile-time dependency injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local project files which serves as a potential vector for indirect prompt injection if the codebase originates from an untrusted source.
  • Ingestion points: Processes **/*.go source files through the wire CLI and gopls LSP integration.
  • Boundary markers: No explicit instructions are provided to the agent to distinguish between code-level instructions and data.
  • Capability inventory: The skill is granted Bash, Read, Write, and Edit capabilities as defined in the skill configuration.
  • Sanitization: The skill relies on the standard Go compiler and the google/wire parser to handle file contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:30 AM
Security Audit — agent-trust-hub — golang-google-wire