Use when packaging a Go project with go.mod, when an element needs go_module sources for offline builds, or when setting up GOPATH vendoring in BuildStream
75
68%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Advisory
Suggest reviewing before use
Optimize this skill with Tessl
npx tessl skill review --optimize ./.opencode/skills/packaging-go-projects/SKILL.mdSecurity
2 findings — 2 medium severity. This skill can be installed but you should review these findings before use.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Third-party content exposure detected (high risk: 1.00). The skill's required workflow uses sources like "kind: git_repo" and "kind: go_module" with github:<org>/<repo>.git and "kind: tar" with github_files URLs in the SKILL.md sources sections, which fetch and stage public GitHub repositories and release tarballs (untrusted third-party content) that the build process reads and acts on, so remote content can influence tool actions and decisions.
The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.
Potentially malicious external URL detected (high risk: 0.90). The skill fetches remote source code at runtime (e.g., git_repo entries like "github:<org>/<repo>.git" and the example "https://github.com/<org>/<repo>" / github_files:<org>/<repo>/releases/download/...) which are required build dependencies and will be compiled/executed as part of the build, so remote content can execute code.
f062bf8
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.