golang-popular-libraries

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process user queries and fetch information from external sources (e.g., awesome-go, pkg.go.dev, and tool outputs) to recommend Go libraries. This behavior exposes the agent to untrusted data from external documentation or search results, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: User prompts, external URLs fetched via WebFetch (e.g., github.com/avelino/awesome-go), and package metadata retrieved through tools like godig.
  • Capability inventory: The skill is granted access to high-privilege tools including Bash, WebFetch, WebSearch, and Agent, which could be targeted by successful injections.
  • Boundary markers: The skill lacks specific instructions to delimit or ignore instructions potentially embedded in external content.
  • Sanitization: There are no explicit requirements for validating or sanitizing the content retrieved from external library documentation or community lists.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:21 PM
Security Audit — agent-trust-hub — golang-popular-libraries