Back to skill

Security audit

golang-lint

Security checks across malware telemetry and agentic risk

Overview

This skill provides Go linting guidance and uses proportionate tools to read, edit, format, and lint Go project files.

Install this if you want an agent to help configure and run golangci-lint on Go projects. Be aware that some workflows tell the agent to run auto-fix and parallel cleanup agents, so review resulting code changes before committing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The description says to use the skill when 'asking about lint warnings or nolint suppressions,' 'setting up code quality tooling,' or 'choosing linters.' These are broad natural-language conditions rather than a constrained trigger list, which increases the chance of unintended invocation outside a clearly bounded Golang linting context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.