golang-observability
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's 'Audit mode' employs multi-agent orchestration to review external Go source code for observability signals.
- Ingestion points: The signal-specific sub-agents (metrics, logging, tracing, profiling, RUM) ingest and process content from Go source files (
**/*.go) using theAgenttool. - Boundary markers: The orchestration instructions lack explicit delimiters or instructions to ignore embedded commands within the audited codebase, which could allow malicious code to influence the sub-agents' analysis.
- Capability inventory: The skill utilizes significant capabilities including
Bashcommands, file operations, and sub-agent creation, which are part of the processing pipeline for external data. - Sanitization: The skill does not describe any sanitization or validation steps for the code content before it is processed by the auditing sub-agents.
- [COMMAND_EXECUTION]: Shell command execution is strictly controlled through tool-prefix constraints in the configuration.
- The
Bashtool is restricted to well-defined prefixes for Go tooling (go:*), linting (golangci-lint:*), and version control (git:*), effectively limiting the agent's execution scope to the project's development workflow. - [EXTERNAL_DOWNLOADS]: Recommends the integration of various observability libraries and SDKs from established sources.
- Mentions vendor-specific tools from the author's ecosystem (
samber/slog-*,samber/oops) and well-known services likePostHog,Segment, andPyroscopefor monitoring and analytics. - These references target official repositories and documentation for legitimate development purposes.
Audit Metadata