go-feature-flag

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends downloading the official goff CLI tool from github.com/thomaspoignant/go-feature-flag and the gofeatureflag/go-feature-flag Docker image. These are standard external resources required for the functionality described.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing setup and testing commands such as go install, docker run, and curl. These are legitimate administrative actions for managing a feature flag service.
  • [REMOTE_CODE_EXECUTION]: The installation of the CLI tool via go install from a remote repository involves the execution of externally sourced code. This is a common pattern for installing developer tools.
  • [PROMPT_INJECTION]: The skill processes external data via flags.goff.yaml and evaluation contexts. Ingestion points: Configuration files and JSON payloads. Boundary markers: Not present. Capability inventory: Includes powerful tools like Bash and Write. Sanitization: Not specified, presenting a potential surface for indirect prompt injection if malicious data is provided in flag configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 07:06 PM