golang-uber-fx
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to analyze and refactor local Go source files, which may contain attacker-controlled instructions in comments or strings.
- Ingestion points: The agent reads project-specific .go files via Read, Glob, Grep, and LSP tools as defined in the paths and allowed-tools configuration.
- Boundary markers: The instructions lack explicit delimiters or warnings to help the agent distinguish between legitimate code logic and potential instructions embedded within the codebase.
- Capability inventory: The skill provides access to Bash, Edit, and Write tools, allowing the agent to execute commands or modify files based on its analysis.
- Sanitization: There are no procedures described to sanitize or validate content retrieved from the local environment before it is used to drive agent actions.
Audit Metadata