Agent skill

Arandu Doctor Findings

by arandu-io in arandu-io/arandu

Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

MITAuto-check passedDevelopment

Install Arandu Doctor Findings

skills CLI
$ npx skills add arandu-io/arandu --skill arandu-doctor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install arandu-io/arandu arandu-doctor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/arandu-io/arandu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/arandu-doctor .claude/skills/arandu-doctor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
arandu-doctor
GitHub stars
281
Token cost
~5.9k tokens
SKILL.md length
3,275 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

  • Works in 4 steps: Read the Why, not the rule name. The… → Fix the cause at the line it names, by… → Never suppress. A finding you cannot fix… → …
  • Interpreting an aru doctor finding before marking an Arandu change finished
  • SKILL.md covers When to use, Before you start, Contracts and imports and Every rule, plus 9 more sections
  • Calls go and bash

What it does

aru doctor runs the Arandu framework's architecture rules as static analysis over the parsed tree, since without it mandatory architecture is just documentation nobody reads. Every finding carries a file, a line, the rule name, what is wrong, and a Why that states what a user of the application would experience; the skill insists on fixing the Why rather than the rule name, fixing the cause at the exact line, and never suppressing a finding, because there is deliberately no ignore comment or allow-list. A finding that cannot be fixed is treated as a design question, and aru doctor --strict is run repeatedly, failing on warnings too, until the output is clean before any other gate runs.

Several findings are explained: grant-not-received, a repository method missing a Grant parameter so any caller gets the row; tenant-from-request, where the tenant is read from a path, body or header instead of the authorized context; repository-without-policy, where no Policy decides access, fixed by writing one that starts by denying everything; resource-not-reauthorized, where a handler authorizes the action but not the specific row; view-data-is-a-map, where a typo in a map key becomes a silent blank page; and raw-output-is-not-a-component, a raw value handed to an unescaped output call, a cross-site-scripting risk a plain escaped call avoids.

When your agent uses it

  • Interpreting an aru doctor finding before marking an Arandu change finished
  • A build passes but something feels architecturally unenforced
  • Investigating a rule name such as tenant-from-request or grant-not-received
  • Deciding whether a finding can be worked around instead of fixed

Example prompts

  • “aru doctor flagged tenant-from-request on this handler. What does that mean and how do I fix it?”
  • “Run aru doctor --strict and walk me through every finding.”
  • “Why can't I just add an ignore comment for this policy-never-opened warning?”

Requirements

  • The aru CLI from the Arandu Go framework

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the Why, not the rule name. The rule name says which check fired;
  2. Fix the cause at the line it names, by moving the code to the row of
  3. Never suppress. A finding you cannot fix is a design question, and the
  4. Run it again until it is clean, then the other gates.

What it can do on your machine

Read from SKILL.md and the folder at commit b8a4273. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Arandu Doctor Findings loads about 5.9k tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 3,275 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~155
When it runs · the whole SKILL.md, loaded when a task matches
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from arandu-io/arandu at commit b8a4273, republished under its MIT licence (© arandu-io). 3,275 words, ~5,926 tokens.

Download SKILL.mdSave it as .claude/skills/arandu-doctor/SKILL.md (or your agent's skills folder).
name
arandu-doctor
description
Read and act on aru doctor, the architecture checker of an Arandu (Go) application. Use when a doctor finding is reported, when a build passes but something feels unenforced, or before declaring any Arandu change finished — it is one of the gates. Also use when the request mentions "lint", "static analysis", "architecture check", "why is this failing", or a rule name such as grant-not-received, tenant-from-request, view-data-is-a-map, raw-output-is-not-a-component, service-takes-http or input-read-by-hand. Covers what each finding means, why it is never suppressed, and what the checker cannot see.
license
MIT

Reading what the doctor says

When to use

aru doctor reported something, a build passes and something still feels unenforced, or a change is about to be called finished -- the doctor is the last gate. Fixing what a finding points at is the family skill of that code; this skill says what the finding means.

Before you start

aru doctor is this framework's architecture rules run as static analysis over the parsed tree. Without it, mandatory architecture is documentation nobody reads. Run the aru the Dockerfile pins -- an older one checks fewer rules, and its clean report says less than it seems to.

Contracts and imports

Every finding carries a file, a line, the rule name, what is wrong, and a Why that says what breaks. An error fails the run; a warning fails it only under --strict. There is no ignore comment and no allow-list. The one marker the doctor reads is //arandu:system-grant <reason>, on or above an auth.SystemGrant call outside a seeder, a job and a command: it excuses system-grant-outside-scope on that line and nothing else, and a marker with no reason excuses nothing.

Every rule

The whole set the doctor checks, with the severity it reports, in the order aru doctor --list prints them. An error fails the run; a warning fails it only under --strict. tests/Unit/DoctorSkill_test.go fails when a row here differs from the list it carries, and, when the aru on PATH is the release the Dockerfile pins, when that list differs from what aru doctor --list prints.

ruleseveritywhat it reports
file-does-not-parseerrora Go file the doctor cannot read, which leaves the rest of the report incomplete
repository-without-policyerroran entity with a repository and no policy
grant-not-receivederroran exported repository method that reaches the database and takes no Grant
grant-not-checkederrora method that takes a Grant and never calls Check on it
grant-check-discardederrora Check whose answer is thrown away, as in _ = g.Check(...)
policy-never-openedwarninga policy that denies every action
action-not-a-constanterroran action built from a value rather than named as a constant
enum-rule-not-derivederror or warningan enum rule that lists cases its type does not declare (error), or repeats the ones it does (warning)
handler-reaches-dataerrora controller, a middleware or a route file that uses the data package beyond data.Query
handler-reaches-the-modelerrora controller, a middleware or a route file that opens a query on a model
controller-reaches-repositoryerrora controller, a middleware or a route file that imports app/Repositories
tenant-from-requesterrora tenant read from the request — a path value, a form field, a query parameter — or a Grant whose tenant came from one
tenant-from-headererrora tenant read from a header
system-grant-without-tenanterrora SystemGrant with an empty tenant
system-grant-outside-scopewarninga SystemGrant outside a seeder, a job and a command
sql-built-with-sprintferrorSQL assembled with fmt.Sprintf
sql-built-by-concatenationerrorSQL assembled by concatenating a value
sensitive-field-not-redactedwarninga struct under app/ with a field named for a secret -- password, secret, token, apikey, cpf and the rest, as a whole word -- whose value reaches a log or JSON sink in the project's code, and that has no LogValue and MarshalJSON
session-not-rotatederrora sign-in that authenticates and keeps the session id it arrived with
csrf-exempt-without-signaturewarninga route that changes state under a path CSRFExcept exempts, whose controller action never calls webhook.Verify
view-data-is-a-maperrora view handed a map
view-does-not-existerrora view name that names no .kyse.go
permission-not-declarederrorcode that uses a permission arandu.mod.toml declares false
permission-not-usedwarninga permission arandu.mod.toml declares true and nothing uses
view-keeps-state-in-the-browsererroran x- or @ attribute with a value in a view
sql-without-tenant-scopeerrora statement on a table other statements scope by tenant_id, without that filter
outbox-not-registerederrorcode that stores domain events in a project that registers no outbox table
resource-not-reauthorizedwarninga method that reads a row and does not authorize the row it read
raw-output-is-not-a-componentwarning{!! x !!} given a value rather than a component call
retired-modulewarningan import of a module whose repository was deleted
import-not-canonicalwarninga framework symbol named through a bridge package rather than through the path aru imports:catalog gives it, in Go -- tests included -- and in a .kyse.go source
test-is-not-runwarninga file named ...Test.go, or a test function in a file whose name does not end in _test.go
test-outside-the-tests-treewarninga test outside tests/ whose name does not end in _internal_test.go
package-clause-is-capitalisedwarninga package clause with a capital letter
scaffolding-shipswarninga file outside the tests that imports test scaffolding
skills-out-of-datewarninga skill under .agents/skills copied from the skeleton or a hyz-is module that is behind what that origin hands out at the version the project pins
skills-missingwarninga skill the skeleton or a required hyz-is module hands out that this project does not have
generated-skill-retiredwarninga skill under .agents/skills whose metadata source is aru@<version>: one make:module wrote, which no generator writes or updates any more
migrations-not-linkedwarningmigrations in a package nothing imports, so aru migrate never sees them
added-column-not-nullablewarninga column added to an existing table without Nullable() or a default
rollback-does-nothingwarninga migration that declares neither a Down nor that it is irreversible
driver-not-linkedwarningan engine .env.example names whose connector the project does not import
profile-not-declaredwarning--profile=performance: a project whose arandu.mod.toml does not list that profile
join-across-aggregateserror--profile=performance: a statement that reads two tables
transaction-across-aggregateserror--profile=performance: a transaction that writes two aggregates
model-query-staleerrora generated query or factory missing, behind its entity, or left from one that is gone
model-core-outside-modelserrorthe model core used outside a package that declares entities
input-read-by-handwarninga controller that reads the form, the query or the body field by field instead of ctx.Bind into the request
validate-called-by-controllerwarninga controller that calls Validate() on the request, or validation.Validate, which is the service's call
json-written-by-handwarninga controller that encodes JSON onto the response writer, or writes its own status with it, instead of a resource and ctx.JSON
invalid-form-answered-by-handwarninga controller that answers a rejected form with a 422 of its own instead of returning the validation.Errors
session-loaded-in-controllerwarninga controller outside app/Http/Controllers/Auth that loads the session instead of reading ctx.User()
redirect-to-literal-pathwarninga redirect in a controller to a path written as a literal rather than a named route
html-template-in-appwarninga file under app/ that imports html/template
service-takes-httpwarninga file under app/Services that names the request, the response writer, the HTTP context, the session, a cookie or template.HTML
service-subpackagewarninga directory under app/Services that holds Go
service-file-too-largewarninga file under app/Services longer than 600 lines
controller-too-many-actionswarninga controller type with more than 12 handler methods
operation-chosen-by-form-fieldwarninga handler that switches on a submitted field to call one service method or another
client-outside-clientswarninga request to another system — an http.Client, http.Get, http.NewRequest, the hesape HTTP client — made under app/ outside app/Clients
model-rule-touches-iowarninga method in the custom block of a model that reaches the database, the network or the clock
fragment-without-partialwarningctx.Fragment given a view outside resources/views/partials
helper-reimplementedwarninga function under app/ that rewrites a helper the catalog already has, such as a slug, a CPF or a BRL formatter
raw-sql-outside-repositorywarninga statement run outside app/Repositories and database/
generated-not-wiredwarningan exported New... constructor under app/Http/Controllers or app/Services that nothing outside the tests names, unless it builds a test double a test constructs
subject-built-by-handwarninga Subject literal outside the tests and database/ that writes its own roles or actions

Procedure

  1. Read the Why, not the rule name. The rule name says which check fired; the Why says what a user of the application would experience. Fix the second one.
  2. Fix the cause at the line it names, by moving the code to the row of "Where each kind of code lives" in AGENTS.md that names its kind -- not by reshaping it until the rule stops matching.
  3. Never suppress. A finding you cannot fix is a design question, and the answer goes in the report.
  4. Run it again until it is clean, then the other gates.
The findings you will meet most

grant-not-received — a repository method takes no auth.Grant. Every caller gets the row, whoever asked. Add the Grant as the parameter before the id, start the method with if err := g.Check(Action...); err != nil { return err } — a Grant that is taken and never checked is grant-not-checked — and take it from the Policy.

tenant-from-request — the tenant is read from a path segment, a form field or a query; tenant-from-header is the same finding for a header. A tenant that arrives with the request is a tenant the caller chose. Read it with auth.Tenant(g).

repository-without-policy — a repository is reachable with no Policy deciding. Write the Policy; the generator writes one that denies everything, and you open it action by action.

resource-not-reauthorized — a method authorized the action and then read one row without authorizing the row. The first call answers "may this caller look at all"; the second answers "may this caller look at this". Skipping the second means any user of the same tenant sees the row.

view-data-is-a-map — a view was handed a map. A typo in a key is then a blank space on a page that answered 200. Declare a struct that embeds view.Page.

raw-output-is-not-a-component — {!! x !!} was given a value rather than a call. The raw form escapes nothing, so a value that ever comes from a person is stored cross-site scripting. Write {{ x }}, which escapes, or return it from a component function.

policy-never-opened — a policy denies every action. On a new module this is correct and expected; it is a warning so that a fresh project is not red on day zero.

retired-module — an import names a module that no longer exists. The line says what replaced it.

import-not-canonical — a file names a symbol through a framework bridge package rather than through the path the symbol lives at: security.Grant for auth.Grant, data.DB for database.DB, fhttp.Context for hhttp.Context. The bridges are old import paths whose symbols are aliases of a component's, kept so code written against them goes on compiling; each is removed in v1.0.0, and until then one type is spelled two ways, file by file. It reads every Go file, tests included, and every .kyse.go source -- its import lines and its local.Name uses, as text, so a sentence in the markup that spells security.Grant counts. The Go aru view:build writes is skipped: the finding goes to the import line of the source it was compiled from. Which path is canonical is read, symbol by symbol, from the framework source at the version go.mod requires; a type the framework declares, such as Router or SessionStore, is canonical where it is. That catalog is read from disk, so on a machine that has not downloaded the version the rule is silent. Import the path the finding names, and keep the framework import only for what the framework declares; aru imports:catalog --fix shows the rewrite for every file and --apply writes it. It is a warning because nothing is wrong yet.

sensitive-field-not-redacted — a struct under app/ has a field whose name carries a sensitive word (password, passwd, secret, token, apikey, creditcard, document, cpf, cnpj; a whole word, singular or plural) and whose type can hold one, and a value of it reaches a log or JSON sink in this project's code -- the message names the sink. slog, fmt and observability.Dump print every field, json.Marshal writes every exported one, and only the type can promise it never leaks. A type nothing logs or encodes is not reported, nor one with LogValue or MarshalJSON, nor one only encoded to JSON whose sensitive fields are all json:"-"; a count such as MaxTokens int is not a secret. It follows a value only inside one function: typed by the signature, by a composite literal, or by a name that is the type's in lower case -- not through another type's field, a call's result or a helper that logs. Add LogValue() slog.Value and MarshalJSON to the type, or tag the field json:"-" when JSON is the only sink.

generated-not-wired — an exported New... constructor under app/Http/Controllers or app/Services is named by no file outside the tests: code nothing constructs is code the router never reaches, its tests pass, and a change to it changes nothing anybody sees. A call from bootstrap/app.go, routes/web.go or another constructor wires it. A test double -- Fake, Stub, Mock, Spy or Dummy as a word of the constructor, of the type it returns or of its file -- that a test constructs is not reported; a service named like production code whose only caller is its own test still is, which is the case the rule exists for. It compares names across the project, not types, so a function of the same name elsewhere hides a finding rather than inventing one. Paste the wiring aru make:module printed into bootstrap/app.go and routes/web.go, or delete what nothing reaches.

model-query-stale — a <Entity>Query.go, or a factory aru model:build renders, is missing, behind its entity, or left over from one that is gone. A build compiles what is on disk, so the application would run against the query of an entity that is not the one in the source. Run aru model:build; in a pipeline that calls go build directly, aru model:build --check asks the same question.

model-core-outside-models — the model core is used outside a package that declares entities, which here is app/Models: a model.NewTable, or a method called on a *model.Table, a *model.Builder or what Base() returns. The core hands back untyped rows, and a query written on it is a second way to reach the table, one the generated query does not describe. Call the generated constructor, models.Notes(db), or write the query as a method on *NoteQuery in the custom block of the entity's file.

Three more checks run only under --profile=performance: profile-not-declared, join-across-aggregates and transaction-across-aggregates. What they report is correct code on the conventional profile, and each says so in its own first lines. The ones above run on every profile.

Show full SKILL.md (932 more words)Show less
The structural warnings

Nineteen rules, from input-read-by-hand to subject-built-by-hand at the end of the table above, report code that works and lives in the wrong place: a controller that reads the form field by field, validates, writes JSON or a 422 by hand, loads the session or redirects to a literal path; a service that takes an HTTP type, sits in a subpackage, or grows past 600 lines; a controller past 12 actions or one that picks the operation from a form field; markup outside a view, a client outside app/Clients, a model rule that reaches the database, the network or the clock, a fragment that is not a partial, a helper written again, SQL outside a repository, a constructor nothing wires, and a Subject that writes its own roles. All are warnings.

The correction for each is the row of "Where each kind of code lives" in AGENTS.md that names the kind of code the finding is about: move the code there, do not reshape it until the rule stops matching. A count rule (service-file-too-large, controller-too-many-actions) says where to look, not that the file is wrong. Each rule reads one function, file or call by name, so a clean report means none of these shapes was found, not that none exists.

The sign-in screens go run github.com/arandu-io/ui@v0.22.0 auth publishes, once wired, report nothing. A finding in app/Http/Controllers/Auth after an older kit is the kit's to fix, and republishing a kit release brings the fix. session-loaded-in-controller does not read that directory at all, because signing in is where a session is first loaded.

The CSRF exemption

csrf-exempt-without-signature is a warning.

  • Reason. CSRFExcept, passed to CSRFProtect in bootstrap/app.go, switches the CSRF check off for every write under a path. It exists for a route another system calls -- a webhook -- which proves who sent it with a signature over the body instead of a cookie and a token, and it is safe on that promise alone. An exempt route that verifies nothing takes a write from any page a signed-in person opens, and from anybody who can reach it.
  • Scope. Every CSRFExcept string literal under bootstrap/; every route under routes/ that changes state (POST, PUT, PATCH, DELETE or any method) whose path the prefix exempts the way the framework matches it -- the path itself, or anything below a prefix that ends in /; and the controller action each such route reaches.
  • Negative. The action calls webhook.Verify from github.com/arandu-io/hesape/webhook (under any import name). A GET under the prefix, a path outside it (/webhooksx for "/webhooks/"), and a path below a prefix written without the slash (/hooks/legacy for "/hooks") are not reported. Known false positive: an action that hands the raw body to a service, helper or middleware that verifies it.
  • Limit. Function-local: only the body of the action the route reaches is read, and nothing it calls is followed. A prefix held in a variable, a handler that is a function literal or a controller the route table does not resolve, and a prefix behind a path parameter are not read. A clean report means no unverified action was found, not that none exists.
  • Fix. Verify in the action before anything trusts the body: webhook.Verify(secrets, timestamp, deliveryID, body, signature) from github.com/arandu-io/hesape/webhook, answering 401 when it fails -- or take the route out of the exempt prefix.

Commands

  • aru doctor, every finding; aru doctor --strict, warnings fail too
  • aru doctor --list, every rule with its severity
  • aru doctor --profile=performance, three more checks for the performance profile
  • aru imports:catalog, the import path of each framework symbol
  • aru model:build, the fix for model-query-stale

Example

The one marker the doctor reads, on a call that has a reason to be outside a seeder, a job and a command:

go
package example

import (
	"context"

	"github.com/arandu-io/hesape/auth"
	"github.com/arandu-io/hesape/database"

	models "<module>/app/Models"
	policies "<module>/app/Policies"
)

// PublishedCount answers how many notes a tenant has published, for an
// operator's report that runs with no subject behind it.
func PublishedCount(ctx context.Context, db *database.DB, tenant string) (int, error) {
	//arandu:system-grant the operator's report runs with no subject; the tenant is the one the operator named
	g := auth.SystemGrant(policies.NoteList, tenant)
	published, err := models.Notes(db).WhereNotNull("published_at").Get(ctx, g)
	return len(published), err
}

Do not

  • Reshape code until a rule stops matching. A finding is about where the code lives; code moved to the right place stops matching because it is right.
  • Treat a warning as noise because it is not an error. Structural rules start as warnings so a new project is not red on day zero, not because they are optional.
  • Write a marker without a reason, or put one on a line it does not excuse.
  • Run an older aru and call the report clean.

Extending it

A project adds no rules and suppresses none. A rule that is wrong about correct code is a bug of the doctor, reported with the file and the line; a rule that should exist is a proposal to the framework.

Wiring

None. The doctor reads the tree as it is; CI runs it on every push, without --strict.

Acceptance test

aru doctor prints no finding on the change. tests/Unit/DoctorSkill_test.go holds the table above to the rule list, and to what aru doctor --list prints when the aru on PATH is the pinned release.

Limits

It reads the parsed tree, not the running program.

  • SQL built from a variable, or held in a package constant, is not inspected. A clean report means no unscoped statement was found, not that none exists.
  • Partition keys are not checked, because nothing in the code declares one.
  • A build tag is invisible to it, so a file excluded from the compiler is still read.
  • Each structural rule reads one function, file or call by name: a clean report means none of those shapes was found, not that none exists.
  • csrf-exempt-without-signature reads only the action a route reaches: a signature checked in a helper the action calls is not seen.

Trust it as evidence, never as proof.

Gates

Run them all, in this order, as AGENTS.md lists them:

sh
export GOWORK=off
aru model:build --check
aru view:build
gofmt -l $(find . -name '*.go' -not -path '*/testdata/*' -not -name '*.kyse.go')
go vet ./...
bash tests/test-layout-guard.sh
go test -race ./...
go build ./...
aru doctor
<!-- arandu:begin custom -->
<!-- arandu:end custom -->

© arandu-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/arandu-doctor of arandu-io/arandu.

Open the folder on GitHubat commit b8a4273

Compare with similar skills

Arandu Doctor Findings next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Arandu Doctor Findings compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Arandu Doctor Findings this skillarandu-io/arandu281—~5.9kAutomated safety check: PassMIT
Golang Continuous Integrationsamber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT
Golang Continuous Integrationcontext-labs/whip1.1k—~3.5kAutomated safety check: PassMIT
Glintspeakeasy-api/gram273—~6.4kAutomated safety check: PassAGPL-3.0
NGINX Ingress Controller Structurenginx/kubernetes-ingress5.1k—~3.8kAutomated safety check: PassApache-2.0
Gograph Go Repository Intelligenceozgurcd/gograph229—~4.8kAutomated safety check: NotesMIT

Similar skills

  • Golang Continuous Integration

    samber/cc-skills-golang

    GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

    3.4k GitHub stars~3.7k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

    1.1k GitHub stars~3.5k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Glint

    speakeasy-api/gram

    Conventions for authoring or editing analyzers in the glint/ Go static-analysis package — Speakeasy's custom golangci-lint plugin built on go/analysis.

    273 GitHub stars~6.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • NGINX Ingress Controller Structure

    nginx/kubernetes-ingress

    Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.

    5.1k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.

    229 GitHub stars~4.8k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it.

    2k GitHub stars~1.1k tokensUpdated 23 days ago
    SecurityAuto-check passed

More from arandu-io/arandu

All 12 skills in this repo
  • Arandu API

    arandu-io/arandu

    Answering a program rather than a person in an Arandu (Go) application -- a JSON Resource, a JSON answer from the same routes the pages use, problem+json errors, bearer-token authentication and…

    281 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Arandu Async

    arandu-io/arandu

    Work that does not happen inside the request in an Arandu (Go) application -- background jobs and the worker, scheduled tasks, domain events through the outbox, listeners, notifications, mail and…

    281 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Arandu Feature

    arandu-io/arandu

    Start here for any change to an Arandu (Go) application that adds or changes behaviour -- "add invoices", "let users publish a post", "send a weekly report", "call the payment provider", "expose…

    281 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Arandu HTTP

    arandu-io/arandu

    Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action…

    281 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Arandu Integrations

    arandu-io/arandu

    Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and…

    281 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Arandu Doctor Findings

What does Arandu Doctor Findings do?

Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. aru doctor runs the Arandu framework's architecture rules as static analysis over the parsed tree, since without it mandatory architecture is just documentation nobody reads. Every finding carries a file, a line, the rule name, what is wrong, and a Why that states what a user of the application would experience; the skill insists on fixing the Why rather than the rule name, fixing the cause at the exact line, and never suppressing a finding, because there is deliberately no ignore comment or allow-list.

When should I use Arandu Doctor Findings?

Arandu Doctor Findings fits situations like: interpreting an aru doctor finding before marking an Arandu change finished; A build passes but something feels architecturally unenforced; investigating a rule name such as tenant-from-request or grant-not-received; deciding whether a finding can be worked around instead of fixed.

How do I install Arandu Doctor Findings in Claude Code?

Run `npx skills add arandu-io/arandu --skill arandu-doctor -a claude-code`. Or copy the skill folder (.agents/skills/arandu-doctor in arandu-io/arandu) into .claude/skills/arandu-doctor in your project. Claude Code loads it when a task matches its description.

How do I install Arandu Doctor Findings in Codex?

Run `npx skills add arandu-io/arandu --skill arandu-doctor -a codex`. Or copy the skill folder (.agents/skills/arandu-doctor in arandu-io/arandu) into .agents/skills/arandu-doctor in your project. Codex loads it when a task matches its description.

Can I use Arandu Doctor Findings in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arandu-io/arandu --skill arandu-doctor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/arandu-doctor, .gemini/skills/arandu-doctor, .github/skills/arandu-doctor and .opencode/skills/arandu-doctor in your project.

What does Arandu Doctor Findings need to run?

Going by SKILL.md and its folder, Arandu Doctor Findings needs the command-line tools its instructions call (go and bash). Our summary lists: The aru CLI from the Arandu Go framework.

Does Arandu Doctor Findings access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Arandu Doctor Findings safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Arandu Doctor Findings use?

Arandu Doctor Findings is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Arandu Doctor Findings use?

About 5.9k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Arandu Doctor Findings?

Skills that share tags, products or a category with Arandu Doctor Findings: Golang Continuous Integration (samber/cc-skills-golang, 3.4k stars), Golang Continuous Integration (context-labs/whip, 1.1k stars), Glint (speakeasy-api/gram, 273 stars) and NGINX Ingress Controller Structure (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Arandu Doctor Findings?

arandu-io (a GitHub organization) maintains it in arandu-io/arandu, which has 281 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 10, 2026.

Source: arandu-io/arandu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.