golang-popular-libraries
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process user queries and fetch information from external sources (e.g.,
awesome-go,pkg.go.dev, and tool outputs) to recommend Go libraries. This behavior exposes the agent to untrusted data from external documentation or search results, which could contain malicious instructions designed to influence the agent's behavior. - Ingestion points: User prompts, external URLs fetched via
WebFetch(e.g.,github.com/avelino/awesome-go), and package metadata retrieved through tools likegodig. - Capability inventory: The skill is granted access to high-privilege tools including
Bash,WebFetch,WebSearch, andAgent, which could be targeted by successful injections. - Boundary markers: The skill lacks specific instructions to delimit or ignore instructions potentially embedded in external content.
- Sanitization: There are no explicit requirements for validating or sanitizing the content retrieved from external library documentation or community lists.
Audit Metadata