golang-modernize

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and reference materials focus entirely on legitimate software development tasks, specifically the modernization of Go source code across versions 1.21 through 1.27.
  • [SAFE]: Shell tool usage is strictly limited via specific command prefixes (go:*, golangci-lint:*, git:*) for the Bash tool, adhering to the principle of least privilege and preventing arbitrary command execution.
  • [SAFE]: The skill actively promotes security improvements in the target codebase, such as replacing manual path validation with the safer os.Root API introduced in Go 1.24 to prevent path traversal attacks (CWE-22).
  • [SAFE]: Remote resources referenced in the instructions are restricted to official Go documentation (go.dev) and the author's own verified GitHub repositories.
  • [SAFE]: The workflow incorporates safety measures for large-scale changes, such as using isolated worktrees to ensure that codebase-wide modernizations can be reviewed before merging into the main project tree.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:39 PM
Security Audit — agent-trust-hub — golang-modernize