golang-graphql

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided GraphQL schema files (.graphql) and Go source code (.go) which are potentially untrusted ingestion points.
  • Ingestion points: Processes project-level Go files and GraphQL SDL files defined in the paths and description fields.
  • Boundary markers: No explicit delimiters are specified for separating schema content from agent instructions.
  • Capability inventory: The skill allows file modification (Edit, Write) and command execution via Bash(go:*) and Bash(git:*).
  • Sanitization: The skill relies on standard agent processing of source code and schemas. While this constitutes a technical attack surface, the skill explicitly instructs the agent to implement safety guardrails like complexity limits and error masking, effectively mitigating standard GraphQL-based risks. Per instruction guidelines, this category is assessed as a low-severity inherent risk rather than a malicious finding.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:30 AM
Security Audit — agent-trust-hub — golang-graphql