golang-graphql
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided GraphQL schema files (.graphql) and Go source code (.go) which are potentially untrusted ingestion points.
- Ingestion points: Processes project-level Go files and GraphQL SDL files defined in the
pathsanddescriptionfields. - Boundary markers: No explicit delimiters are specified for separating schema content from agent instructions.
- Capability inventory: The skill allows file modification (
Edit,Write) and command execution viaBash(go:*)andBash(git:*). - Sanitization: The skill relies on standard agent processing of source code and schemas. While this constitutes a technical attack surface, the skill explicitly instructs the agent to implement safety guardrails like complexity limits and error masking, effectively mitigating standard GraphQL-based risks. Per instruction guidelines, this category is assessed as a low-severity inherent risk rather than a malicious finding.
Audit Metadata