golang-performance
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration specifies the installation of the
benchstatutility from the official Go performance repository atgolang.org/x/perf/cmd/benchstat@latest. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze Go source code from the local workspace to provide performance recommendations, creating a potential surface for indirect injection if analyzing malicious code.
- Ingestion points: The skill identifies and reads Go files (
**/*.go) usingRead,Glob, andGreptools. - Boundary markers: No specific delimiters or instructions to ignore embedded prompts in analyzed code were identified.
- Capability inventory: The skill possesses broad capabilities including file modification (
Write,Edit) and shell command execution viaBash(specifically forgo,curl,perf, andbenchstat). - Sanitization: No explicit sanitization or filtering of ingested source code content was observed.
Audit Metadata