Bom Explore
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS.
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openshift-eng/ai-helpers native-fips --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/golang/skills/native-fips .claude/skills/native-fips && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "native-fips" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fips into .claude/skills/native-fips/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-fips", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fipsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openshift-eng/ai-helpers native-fips --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/golang/skills/native-fips .agents/skills/native-fips && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "native-fips" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fips into .agents/skills/native-fips/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-fips", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openshift-eng/ai-helpers native-fips --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/golang/skills/native-fips .cursor/skills/native-fips && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "native-fips" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fips into .cursor/skills/native-fips/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-fips", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openshift-eng/ai-helpers.git --path plugins/golang/skills/native-fips--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openshift-eng/ai-helpers native-fips --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/golang/skills/native-fips .gemini/skills/native-fips && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "native-fips" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fips into .gemini/skills/native-fips/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-fips", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openshift-eng/ai-helpers native-fipsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/golang/skills/native-fips .github/skills/native-fips && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "native-fips" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fips into .github/skills/native-fips/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-fips", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openshift-eng/ai-helpers native-fips --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/golang/skills/native-fips .opencode/skills/native-fips && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "native-fips" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/golang/skills/native-fips into .opencode/skills/native-fips/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "native-fips", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
native-fipsConfigure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS.
Native Fips is an agent skill from openshift-eng/ai-helpers. Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS. Use when the user wants to enable FIPS compliance in a Go project, migrate from openssl-based FIPS to native Go FIPS, or when build configs contain GOEXPERIMENT=strictfipsruntime or openssl-based FIPS patterns. Triggers on: 'native FIPS', 'GOFIPS140', 'FIPS without openssl', 'enable FIPS', 'migrate FIPS', 'GOEXPERIMENT=strictfipsruntime', 'strictfipsruntime', 'fips140', 'Go FIPS module'.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cryptography. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comgitlab.comimages.redhat.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Native Fips loads about 2k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 837 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 837 words, ~1,958 tokens.
.claude/skills/native-fips/SKILL.md (or your agent's skills folder).Configure a Go project to use Go's native FIPS 140 module (GOFIPS140). With CGO_ENABLED=0, this produces static binaries that no longer depend on the openssl RPM. Projects that require cgo should keep CGO_ENABLED=1 and adjust their FIPS setup accordingly. Works for both new projects and migrating existing openssl-based FIPS setups.
GOFIPS140Tells the Go compiler which FIPS 140 crypto module to embed into the binary.
| Value | Status | ML-KEM | ML-DSA | Notes |
|---|---|---|---|---|
v1.0.0 | Validation completed | Yes | No | Validated, stable |
v1.26.0 | Module In Process (MIP) | Yes | Yes | Adds ML-DSA + better entropy |
latest | Alias | — | — | Resolves to newest available module |
certified | Alias | — | — | Resolves to newest FIPS-certified module |
Use certified in go build as it automatically resolves to the latest certified module (currently v1.0.0). Both modules support ML-KEM (post-quantum key encapsulation), so post-quantum key exchange is available without the old DEFAULT:PQ crypto-policies stage.
GOEXPERIMENT=strictfipsruntime (downstream only)The downstream golang-fips/go toolchain (used in RHEL/CentOS Go Toolset) provides GOEXPERIMENT=strictfipsruntime, which adds a startup check that panics if the binary's FIPS configuration is incompatible with the host environment. This is separate from GOFIPS140 — it provides fail-closed startup enforcement, not module selection.
When migrating a downstream build from the OpenSSL backend to native FIPS on 1.26+ builders, retain GOEXPERIMENT=strictfipsruntime and add -tags no_openssl to disable the OpenSSL backend. The 1.26+ builders imply GODEBUG=fips140=auto whenever the FIPS module is compiled in, so the binary works on both FIPS and non-FIPS hosts:
CGO_ENABLED=0 GOFIPS140=v1.26.0 GOEXPERIMENT=strictfipsruntime go build -tags no_openssl ...For upstream Go (which has no strictfipsruntime or OpenSSL backend):
CGO_ENABLED=0 GOFIPS140=certified go build ...GODEBUG=fips140=<value>Controls FIPS activation at runtime. You almost never need to set this explicitly. When a binary is built with GOFIPS140, the toolchain sets an appropriate default: upstream Go defaults to fips140=on, and the downstream golang-fips/go toolchain defaults (or will soon default) to fips140=auto. Only override this if you need behavior different from the toolchain default.
| Value | Behavior | Availability |
|---|---|---|
fips140=auto | Follow the host's FIPS setting (/proc/sys/crypto/fips_enabled) | Downstream golang-fips/go only |
fips140=on | Always enable FIPS, regardless of host | Upstream Go and downstream |
fips140=only | Best-effort FIPS-only mode — non-FIPS crypto calls may return an error or panic. May produce false positives/negatives. Test and assessment only — not for production. | Upstream Go and downstream |
Upstream Go (go.dev) supports off, on, and only. The auto value is provided by the downstream golang-fips/go toolchain.
Go 1.24+ includes crypto/mlkem (FIPS 203) and crypto/tls uses X25519MLKEM768 by default for TLS connections. This means ML-KEM is built into the binary — no OS-level crypto-policies configuration is needed.
The old approach required a separate crypto-policies setup (via RPM or manual config) to enable DEFAULT:PQ. This configured system C libraries (OpenSSL, GnuTLS, NSS, etc.) by generating per-library config files in /etc/crypto-policies/back-ends/:
| Backend file | Library |
|---|---|
openssl.config / opensslcnf.config | OpenSSL |
gnutls.config | GnuTLS |
nss.config | NSS (Mozilla) |
openssh.config / opensshserver.config | OpenSSH |
java.config | Java/OpenJDK |
krb5.config | Kerberos |
libssh.config | libssh |
The :PQ subpolicy prepends hybrid ML-KEM groups at highest priority, adding X25519MLKEM768, P256-MLKEM768, P384-MLKEM1024 etc. to each backend in its native syntax.
Why this is unnecessary for Go binaries: A statically-compiled Go binary (CGO_ENABLED=0) with GOFIPS140 uses its own crypto/tls stack — it does not link against OpenSSL, GnuTLS, or NSS. OS-level crypto-policies back-end configs have zero effect on Go binaries. Such binaries have no runtime library dependencies, so they can run in minimal scratch-like images such as Hardened Images - Static.
The tls-scanner tool can verify endpoint TLS compliance on a running cluster — it connects to pod endpoints and checks their TLS configuration (protocol versions, cipher suites, and with PQC_CHECK=true, TLS 1.3 and ML-KEM readiness). It does not verify binary-level FIPS properties such as GOFIPS140 module embedding, runtime FIPS activation, or non-TLS cryptographic usage.
The tool source and documentation is at https://github.com/openshift/tls-scanner. The tls-scanner-run step ref is defined in the openshift/release step registry at ci-operator/step-registry/tls/scanner/run/.
| Parameter | Default | Description |
|---|---|---|
SCAN_NAMESPACE | "" (all) | Comma-separated namespaces to scan. Empty scans all namespaces. |
PQC_CHECK | "false" | Set "true" to check post-quantum cryptography readiness (TLS 1.3 + ML-KEM support). |
SCANNER_NAMESPACE | "" | Namespace where the scanner pod is deployed. Empty creates a dedicated tls-scanner namespace. |
SCAN_LIMIT_IPS | "" | Max IPs to scan (empty/0 = no limit). Useful for smoke testing. |
TLS_PROFILE_TYPE | "" | Expected TLS profile type (Old, Intermediate, Modern). When set, overrides reading from APIServer/cluster. |
TLS_SCANNER_CLUSTER_LABEL | "" | HyperShift target: "management" or "guest". Empty scans via the step's KUBECONFIG. |
| Name | Type | Values | Description |
|---|---|---|---|
GOFIPS140 | Build env var | certified, latest, v1.0.0, v1.26.0 | Selects which FIPS 140 crypto module to embed. certified resolves to the latest validated module. |
GOEXPERIMENT=strictfipsruntime | Build env var | (flag) | Downstream only. Adds a startup panic if FIPS config is incompatible with the host. |
CGO_ENABLED | Build env var | 0, 1 | 0 produces a static binary with no C dependencies. 1 links against C libraries (needed if the project requires cgo). |
-tags no_openssl | Build tag | (flag) | Disables the downstream OpenSSL crypto backend so the binary uses only Go's native FIPS module. Not needed for upstream Go. |
fips140v1.26 | Synthesized build tag | (automatic) | Injected by the toolchain when GOFIPS140=v1.26.0 is set. Not user-specified. |
GODEBUG=fips140 | Runtime env var | auto, on, only, off | Controls FIPS activation at runtime. Rarely needs to be set — the toolchain picks the right default when built with GOFIPS140. auto is downstream only. |
© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/golang/skills/native-fips of openshift-eng/ai-helpers.
Open the folder on GitHubat commit a627176
Native Fips next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Native Fips this skillopenshift-eng/ai-helpers | 120 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Bom Explorecdxgen/cdxgen | 1.1k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Webcrypt MCPputervision/state-memory-mcp | 114 | — | ~847 | Automated safety check: Pass | MIT | |
| Crypto Analysishypnguyen1209/offensive-claude | 388 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Security Reviewvalory-xyz/open-autonomy | 129 | — | ~11k | Automated safety check: Notes | Apache-2.0 | |
| Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.3k | Automated safety check: Notes | Custom licence |
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
putervision/state-memory-mcp
Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.
hypnguyen1209/offensive-claude
A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…
valory-xyz/open-autonomy
Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…
AgentSecOps/SecOpsAgentKit
Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.
internet-court/internet-court-skill
A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…
openshift-eng/ai-helpers
Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.
openshift-eng/ai-helpers
Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.
openshift-eng/ai-helpers
Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.
openshift-eng/ai-helpers
Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.
openshift-eng/ai-helpers
Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.
openshift-eng/ai-helpers
Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file
Categories
Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS. Native Fips is an agent skill from openshift-eng/ai-helpers. Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS.
Native Fips fits situations like: the user wants to enable FIPS compliance in a Go project; migrate from openssl-based FIPS to native Go FIPS; build configs contain GOEXPERIMENT=strictfipsruntime; openssl-based FIPS patterns.
Run `npx skills add openshift-eng/ai-helpers --skill native-fips -a claude-code`. Or copy the skill folder (plugins/golang/skills/native-fips in openshift-eng/ai-helpers) into .claude/skills/native-fips in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openshift-eng/ai-helpers --skill native-fips -a codex`. Or copy the skill folder (plugins/golang/skills/native-fips in openshift-eng/ai-helpers) into .agents/skills/native-fips in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill native-fips -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/native-fips, .gemini/skills/native-fips, .github/skills/native-fips and .opencode/skills/native-fips in your project.
Going by SKILL.md and its folder, Native Fips needs the command-line tools its instructions call (go).
SKILL.md names 3 domains. As links in the text: github.com, gitlab.com and images.redhat.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Native Fips is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Native Fips: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 114 stars), Crypto Analysis (hypnguyen1209/offensive-claude, 388 stars) and Security Review (valory-xyz/open-autonomy, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.
Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.