golang-observability

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's 'Audit mode' employs multi-agent orchestration to review external Go source code for observability signals.
  • Ingestion points: The signal-specific sub-agents (metrics, logging, tracing, profiling, RUM) ingest and process content from Go source files (**/*.go) using the Agent tool.
  • Boundary markers: The orchestration instructions lack explicit delimiters or instructions to ignore embedded commands within the audited codebase, which could allow malicious code to influence the sub-agents' analysis.
  • Capability inventory: The skill utilizes significant capabilities including Bash commands, file operations, and sub-agent creation, which are part of the processing pipeline for external data.
  • Sanitization: The skill does not describe any sanitization or validation steps for the code content before it is processed by the auditing sub-agents.
  • [COMMAND_EXECUTION]: Shell command execution is strictly controlled through tool-prefix constraints in the configuration.
  • The Bash tool is restricted to well-defined prefixes for Go tooling (go:*), linting (golangci-lint:*), and version control (git:*), effectively limiting the agent's execution scope to the project's development workflow.
  • [EXTERNAL_DOWNLOADS]: Recommends the integration of various observability libraries and SDKs from established sources.
  • Mentions vendor-specific tools from the author's ecosystem (samber/slog-*, samber/oops) and well-known services like PostHog, Segment, and Pyroscope for monitoring and analytics.
  • These references target official repositories and documentation for legitimate development purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:39 PM
Security Audit — agent-trust-hub — golang-observability