golang-samber-ro

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the samber/ro library using the standard command go get github.com/samber/ro. This is an expected development task targeting the author's official repository.
  • [COMMAND_EXECUTION]: The documentation includes a reference to the plugins/proc module, which allows for process execution within reactive pipelines. This is presented as a feature for system integration tasks.
  • [INDIRECT_PROMPT_INJECTION]: The library is designed to ingest and process data from external, potentially untrusted sources such as HTTP streams, file system changes via fsnotify, and JSON payloads.
  • Ingestion points: Data entry points include the http, fsnotify, and encoding/json plugins mentioned in SKILL.md and references/plugin-ecosystem.md.
  • Boundary markers: The provided code examples and patterns do not specify explicit delimiters or isolation for untrusted input within the reactive streams.
  • Capability inventory: The library provides powerful data transformation and execution capabilities, including FlatMap and process execution through the proc plugin.
  • Sanitization: While a validation plugin (ozzo-validation) is mentioned, specific sanitization practices for preventing prompt injection in stream-processed data are not detailed in the references.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:11 PM
Security Audit — agent-trust-hub — golang-samber-ro