golang-pkg-go-dev

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing the godig utility from github.com/samber/godig/cmd/godig@latest. This is a vendor-owned resource hosted on GitHub.
  • [COMMAND_EXECUTION]: The skill executes godig and other Go-related commands (go, git, golangci-lint) via the Bash tool. These operations are restricted to the specified binaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the Go ecosystem. \n
  • Ingestion points: Data is fetched from pkg.go.dev via godig overview, godig package doc, and godig module readme. \n
  • Boundary markers: Results are formatted as Markdown (-o md), but there are no explicit instructions for the agent to ignore potentially malicious prompts embedded in the external documentation. \n
  • Capability inventory: The agent has access to Bash command execution and other file manipulation tools listed in allowed-tools. \n
  • Sanitization: The skill does not perform sanitization or filtering on the retrieved documentation text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:42 PM
Security Audit — agent-trust-hub — golang-pkg-go-dev