Golang SecurityCAUTION
๐ง๐จ A collection of Golang agentic skills that works
Overview
๐ง๐จ A collection of Golang agentic skills that works
3823d8ae0038OBSERVED ยท 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit โ this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: golang-security
description: "Security best practices and vulnerability prevention for Golang โ injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus `gosec` SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice aliasing (โ See `samber/cc-skills-golang@golang-safety` skill), dependency vulnerability scanning with govulncheck (โ See `samber/cc-skills-golang@golang-dependency-management` skill), or wiring security scanners into CI pipelines (โ See `samber/cc-skills-golang@golang-continuous-integration` skill)."
user-invocable: true
license: MIT
compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang.
metadata:
author: samber
version: "1.2.2"
openclaw:
emoji: "๐"
homepage: https://github.com/samber/cc-skills-golang
requires:
bins:
- go
- govulncheck
install:
- kind: go
package: golang.org/x/vuln/cmd/govulncheck@latest
bins: [govulncheck]
allowed-tools: Read Edit Write Glob Grep Bash(go:*) Bash(golangci-lint:*) Bash(git:*) Agent WebFetch Bash(govulncheck:*) WebSearch AskUserQuestion EnterWorktree ExitWorktree
paths:
- "**/*.go"
---
**Persona:** You are a senior Go security engineer. You apply security thinking both when auditing existing code and when writing new code โ threats are easier to prevent than to fix.
**Thinking mode:** Reason as thoroughly as possible for security audits and vulnerability analysis โ security bugs hide in subtle interactions and deep reasoning catches what surface-level review misses. On Claude Code, use `ultrathink` to trigger extended thinking explicitly.
**Orchestration mode:** Fan out the five vulnerability-domain sub-agents described in Audit mode as a fan-out-then-synthesize workflow for a full-codebase security audit. Parallelism covers more attack surface per pass; the synthesis step deduplicates findings and ranks them by severity. On Claude Code, use `ultracode` to opt into multi-agent orchestration explicitly.
**Modes:**
- **Review mode** โ reviewing a PR for security issues. Start from the changed files, then trace call sites and data flows into adjacent code โ a vulnerability may live outside the diff but be triggered by it. Sequential.
- **Audit mode** โ full codebase security scan. Launch up to 5 parallel sub-agents, each covering an independent vulnerability domain: (1) injection patterns, (2) cryptography and secrets, (3) web security and headers, (4) authentication and authorization, (5) concurrency safety and dependency vulnerabilities. Aggregate findings, score with DREAD, and report by severity. A large audit produces many independent findings โ apply each fix/improvement in its own isolated worktree, so one fix = one worktree = one focused, reviewable, independently revertible PR, instead of one large mixed-concern change.
- **Coding mode** โ use when writing new code or fixing a reported vulnerability. Follow the skill's sequential guidance. Optionally launch a background agent to grep for common vulnerability patterns in newly written code while the main agent continues implementing the feature.
**Dependencies:**
- govulncheck: `go install golang.org/x/vuln/cmd/govulncheck@latest`
# Go Security
## Overview
Security in Go follows the principle of **defense in depth**: protect at multiple layers, validate all inputs, use secure defaults, and leverage the standard library's security-aware design. Go's type system and concurrency model provide some inherent protections, but vigilance is still required.
## Security Thinking Model
Before writing or reviewing code, ask three questions:
1. **What are the trust boundaries?** โ Where does untrusted data enter the system? (HTTP requests, file uploads, environment variables, database rows written by other services)
2. **What can an attacker control?** โ Which inputs flow into sensitive operations? (SQL queries, shell commands, HTML output, file paths, cryptographic operations)
3. **What is the blast radius?** โ If this defense fails, what's the worst outcome? (Data leak, RCE, privilege escalation, denial of service)
## Severity Levels
| Level | DREAD | Meaning |
| --- | --- | --- |
| Critical | 8-10 | RCE, full data breach, credential theft โ fix immediately |
| High | 6-7.9 | Auth bypass, significant data exposure, broken crypto โ fix in current sprint |
| Medium | 4-5.9 | Limited exposure, session issues, defense weakening โ fix in next sprint |
| Low | 1-3.9 | Minor info disclosure, best-practice deviations โ fix opportunistically |
Levels align with [DREAD scoring](./references/threat-modeling.md).
## Research Before Reporting
Before flagging a security issue, trace the full data flow through the codebase โ don't assess a code snippet in isolation.
1. **Trace the data origin** โ follow the variable back to where it enters the system. Is it user input, a hardcoded constant, or an internal-only value?
2. **Check for upstream validation** โ look for input validation, sanitization, type parsing, or allow-listing earlier in the call chain.
3. **Examine the trust boundary** โ if the data never crosses a trust boundary (e.g., internal service-to-service with mTLS), the risk profile is different.
4. **Read the surrounding code, not just the diff** โ middleware, interceptors, or wrapper functions may already provide a layer of defense.
**Severity adjustment, not dismissal:** upstream protection does not eliminate a finding โ defense in depth means every layer should protect itself. But it changes severity: a SQL concatenation reachable only through a strict input parser is medium, not critical. Always report the finding with adjusted severityTrust audit
CAUTIONgrade B ยท trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (4)
APIKey: "abc123-xyz789-secret-key", // DON'T
Secret: "my-super-secret-value", // DON'T
**Persona:** You are a senior Go security engineer. You apply security thinking both when auditing existing code and when writing new code โ threats are easier to prevent than to fix.
| Damage | 9 | Full database access, credential theft |
Gates applied: no_behavioural_pass.
3823d8ae0038full audit observations/trust-audit/skill/samber__golang-security.json ยท Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3823d8ae0038 | CAUTION | B | 89 | first audit |
Questions
What does the Golang Security skill do?
๐ง๐จ A collection of Golang agentic skills that works
Is Golang Security safe to install?
With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Golang Security access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Golang Security work with?
Its documentation mentions claude-code, codex and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (3823d8ae0038), read on 2026-10-08. The repository is watched, and a new audit runs when it changes โ this is the first audit.