golang-performance

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration specifies the installation of the benchstat utility from the official Go performance repository at golang.org/x/perf/cmd/benchstat@latest.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze Go source code from the local workspace to provide performance recommendations, creating a potential surface for indirect injection if analyzing malicious code.
  • Ingestion points: The skill identifies and reads Go files (**/*.go) using Read, Glob, and Grep tools.
  • Boundary markers: No specific delimiters or instructions to ignore embedded prompts in analyzed code were identified.
  • Capability inventory: The skill possesses broad capabilities including file modification (Write, Edit) and shell command execution via Bash (specifically for go, curl, perf, and benchstat).
  • Sanitization: No explicit sanitization or filtering of ingested source code content was observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:10 PM
Security Audit — agent-trust-hub — golang-performance