Back to skill

Security audit

go-dev

Security checks for vulnerabilities and agentic risk

Overview

This Go development skill is mostly coherent, but it recommends high-impact setup commands that execute mutable remote code and install persistent project hooks.

Review the install commands before use. Prefer downloading verified release artifacts or using a trusted package manager instead of piping a remote script into sh, pin Docker images, and only allow the skill to run formatters, git-hook installation, or database migration commands when you explicitly intend those changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The skill recommends piping a remotely fetched shell script directly into sh, which executes unverified code from the network immediately. If the remote host, transport, DNS, CDN, or upstream script is compromised, users can suffer arbitrary code execution on their development machines or CI runners.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
mkdir -p cmd/myapp internal migrations

# 3. Install golangci-lint as a binary, not as a module tool (see note below)
curl -sSfL https://golangci-lint.run/install.sh | sh -s -- -b $(go env GOPATH)/bin v2.14.0

# 4. Track the rest in go.mod (Go 1.24+ tool directive). Pin versions - never @latest,
#    which recompiles the tool on every CI run and drifts between machines.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 444)May include surrounding context.

md
**Config placement is load-bearing.** `.golangci.yml` must sit at the repo root: golangci-lint searches the working dir and its parents, and editor Go plugins auto-detect only a root `.golangci.*`, so filing it under `.github/` costs in-IDE linting even if you pass `--config`. lefthook auto-discovers only the repo root or `.config/` - move `lefthook.yml` anywhere else and commits silently stop running hooks, because git invokes the hook directly and no task-runner recipe can intercept that.

**lefthook is dormant until installed.** The binary being absent from PATH, or `lefthook install` never having run, both present as "hooks just don't fire" with no warning. Set `assert_lefthook_installed: true` so this fails loudly, pin lefthook as a repo tool, and make `lefthook install` part of onboarding. A leftover `core.hooksPath` (husky, pre-commit) is a third cause: `lefthook install` stops when it is set, until you run `lefthook install --reset-hooks-path`.

**A stale lint cache invents issues.** golangci-lint can report failures in files that no longer exist on disk - typically after a branch switch or a deleted worktree. The costlier variant is nolintlint reporting a load-bearing `//nolint` directive as unused, which tempts you to delete a real suppression. Its main root cause was lost analyzer facts after an interrupted run, a changed linter set, or a partly cleaned cache ([#6807](https://github.com/golangci/golangci-lint/issues/6807)), fixed in v2.14.0 - so upgrade before debugging. The same bug can also *hide* real issues that CI then catches. Prove which side is lying with `GL_DEBUG=nolint_filter` before touching the code. If a phantom persists, move that suppression into `linters.exclusions.rules` rather than running `golangci-lint cache clean` before every gate, which turns a warm run of seconds into a cold one ten times longer. `cache clean` empties whatever `GOLANGCI_LINT_CACHE` resolves to in *that* shell, so running it outside a recipe that sets the variable 
...[truncated 25 chars]

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This repeats the same unsafe pattern in the migration section, again encouraging direct execution of a network-retrieved shell script. Repetition increases exposure because users following either setup path may run arbitrary upstream code without validation.

Content

Scanner excerpt · SKILL.md (reported line 525)May include surrounding context.

bash
# 1. Install tools (golangci-lint as a binary - see Quick Start)
curl -sSfL https://golangci-lint.run/install.sh | sh -s -- -b $(go env GOPATH)/bin v2.14.0
go install mvdan.cc/gofumpt@v0.12.0
go install gotest.tools/gotestsum@v1.13.0

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 565)May include surrounding context.

md
- [gotestsum Reference](references/gotestsum-reference.md) - output formats, watch mode, JUnit XML, CI recipes

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 568)May include surrounding context.

md
- [Justfile Reference](references/justfile-reference.md) - Go-specific recipes, task groups, lefthook integration

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The documented Docker command uses --network host, which removes normal container network isolation and gives the container direct access to the host network namespace. If users run this pattern broadly, especially with untrusted images or on shared systems, it increases exposure to host services and weakens defense-in-depth; combined with an unpinned image, the risk is materially higher.

Content

Scanner excerpt · references/go-migrate-reference.md (reported line 31)May include surrounding context.

go install -tags 'postgres' github.com/golang-migrate/migrate/v4/cmd/migrate@v4.20.1

Docker

docker run -v $(pwd)/migrations:/migrations --network host migrate/migrate
-path=/migrations/ -database "postgres://localhost:5432/db" up

text

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

Piping a remotely fetched script directly into sh executes unverified code immediately, creating a classic supply-chain and remote code execution risk. If the hosting domain, CDN path, TLS trust chain, or upstream release process is compromised, a user running this command would execute attacker-controlled shell code on their machine or CI runner.

Content

Scanner excerpt · references/golangci-lint-reference.md (reported line 11)May include surrounding context.

bash
# Binary (recommended)
curl -sSfL https://golangci-lint.run/install.sh | sh -s -- -b $(go env GOPATH)/bin v2.14.0

# Homebrew - "Homebrew can use an unexpected version of Go to build the binary",
# and it cannot pin a version. Prefer the binary installer.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/justfile-reference.md (reported line 22)May include surrounding context.

just
set shell := ["bash", "-euo", "pipefail", "-c"]   # Strict bash: errexit, undefined vars, pipefail
set dotenv-load                                    # Load .env file

# Recipe with doc comment
recipe-name:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/justfile-reference.md (reported line 154)May include surrounding context.

just
set shell := ["bash", "-euo", "pipefail", "-c"]   # Strict bash: errexit, undefined vars, pipefail
set dotenv-load                                    # Load .env file

# Recipe with doc comment
recipe-name:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/justfile-reference.md (reported line 161)May include surrounding context.

just
set shell := ["bash", "-euo", "pipefail", "-c"]   # Strict bash: errexit, undefined vars, pipefail
set dotenv-load                                    # Load .env file

# Recipe with doc comment
recipe-name:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/justfile-reference.md (reported line 159)May include surrounding context.

md
set quiet                         # Suppress command echo by default
set positional-arguments          # Pass args as $1, $2, etc.

set dotenv-path := ".env.local"   # Load a specific env file
set dotenv-required               # Fail if the env file is missing
set dotenv-override               # .env wins over the ambient environment
set working-directory := "backend"  # Default dir for every recipe

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/lefthook-reference.md (reported line 177)May include surrounding context.

md
| `lefthook dump` | Print the merged effective config |
| `lefthook add <hook>` | Scaffold a hook and its script directory |
| `lefthook check-install` | Report whether hooks are installed |
| `lefthook self-update` | Update the binary in place |
| `lefthook version` | Print the version (`--full` includes the commit) |

Three install behaviours worth knowing:

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The Docker example references migrate/migrate without an explicit tag or digest, which makes the command non-reproducible and vulnerable to supply-chain drift if the image changes upstream. In documentation that users may copy directly into CI or local admin workflows, this can result in unexpectedly pulling a different image than intended, including one with breaking changes or newly introduced vulnerabilities.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/go-migrate-reference.md (reported line 96)May include surrounding context.

md
# Revert ALL (interactive confirmation)
migrate -path migrations -database "$DATABASE_URL" down

# Revert all without confirmation
migrate -path migrations -database "$DATABASE_URL" down -all

# Check current version

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/gofumpt-reference.md (reported line 40)May include surrounding context.

text

**Flags:**
- `-w` - write result to file (instead of stdout)
- `-l` - list files that differ
- `-d` - display diff (non-zero exit if any diff, since v0.8.0)
- `-extra` - enable extra rules. **Changed in v0.10.0:** "The `-extra` flag now accepts a comma-separated list of rule names to enable individual extra rules, rather than enabling all of them at once." Bare `-extra` still enables all of them: `Extra` reports `IsBoolFlag() == true` (format/format.go), so the flag package calls `Set("true")`, the same branch that sets `GroupParams`, `ClotheReturns` **and** `BalanceCalls`. Prefer the explicit `-extra=group_params,clothe_returns` to stay off the controversial `balance_calls`. Names are underscore-separated, comma-joined, and must follow `=` - as a bool flag, `-extra group_params` would treat `group_params` as a path. An unknown name fails with `unknown rule`

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/justfile-reference.md (reported line 101)May include surrounding context.

md
# Platform-specific
[linux]
install:
    sudo cp myapp /usr/local/bin/

[macos]
install:

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents commands such as gofumpt -w . and gofumpt -w main.go that write changes directly to files. Although -w is later defined as writing results to file, the usage examples themselves do not prominently warn users that these commands will modify files in place and may create broad one-time diffs.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/golangci-lint-reference.md (reported line 18)May include surrounding context.

md
brew install golangci-lint

# Docker
docker run --rm -v $(pwd):/app -w /app golangci/golangci-lint:v2.14.0 golangci-lint run

# mise (uses the aqua backend, so it fetches the GitHub binary)
mise use -g golangci-lint@2.14.0

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file recommends golangci-lint run --fix and golangci-lint fmt, both of which modify source files, but the surrounding guidance does not give a clear safety warning near the commands themselves that they will edit the working tree. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or project state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.