golang-spf13-viper

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for ingesting configuration data from external, potentially untrusted sources, which creates a surface for indirect prompt injection if the inputs contain malicious instructions.
  • Ingestion points: Configuration enters the agent's context through ReadInConfig for files, AutomaticEnv for environment variables, and ReadRemoteConfig for remote Key-Value stores like etcd and Consul, as described in references/sources-and-formats.md and references/binding-and-env.md.
  • Boundary markers: The instructions do not specify explicit delimiters or instructions for the agent to ignore embedded commands within the configuration values.
  • Capability inventory: The skill is configured with powerful tools including Write, Edit, Bash, Agent, and WebFetch in SKILL.md.
  • Sanitization: The skill advocates for structural validation via Go's type system and explicitly recommends a "validate-then-swap" pattern for hot reloads in references/watch-and-reload.md to mitigate the impact of malformed inputs.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the well-known spf13/viper library and integration with standard remote configuration services.
  • Evidence: SKILL.md provides the go get github.com/spf13/viper@latest command. references/sources-and-formats.md details connections to established remote providers such as etcd and Consul. These represent standard development practices.
  • [COMMAND_EXECUTION]: The skill utilizes standard Go CLI tools for dependency management.
  • Evidence: The go get command is included in SKILL.md to allow the agent to manage project dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:30 AM
Security Audit — agent-trust-hub — golang-spf13-viper