Agent skill

Native Fips

by openshift-eng in openshift-eng/ai-helpers

Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS.

Apache-2.0Auto-check passedSecurity

Install Native Fips

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill native-fips -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers native-fips --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/golang/skills/native-fips .claude/skills/native-fips && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
native-fips
GitHub stars
120
Token cost
~2k tokens
SKILL.md length
837 words
Files
1
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS.

  • The user wants to enable FIPS compliance in a Go project
  • SKILL.md covers Reference, Verification with tls-scanner and Glossary
  • Calls go
  • Migrate from openssl-based FIPS to native Go FIPS

What it does

Native Fips is an agent skill from openshift-eng/ai-helpers. Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS. Use when the user wants to enable FIPS compliance in a Go project, migrate from openssl-based FIPS to native Go FIPS, or when build configs contain GOEXPERIMENT=strictfipsruntime or openssl-based FIPS patterns. Triggers on: 'native FIPS', 'GOFIPS140', 'FIPS without openssl', 'enable FIPS', 'migrate FIPS', 'GOEXPERIMENT=strictfipsruntime', 'strictfipsruntime', 'fips140', 'Go FIPS module'.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • The user wants to enable FIPS compliance in a Go project
  • Migrate from openssl-based FIPS to native Go FIPS
  • Build configs contain GOEXPERIMENT=strictfipsruntime
  • Openssl-based FIPS patterns

Example prompts

  • “native FIPS”
  • “GOFIPS140”
  • “FIPS without openssl”
  • “/native-fips”

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • gitlab.com
    • images.redhat.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Native Fips loads about 2k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 837 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 837 words, ~1,958 tokens.

Download SKILL.mdSave it as .claude/skills/native-fips/SKILL.md (or your agent's skills folder).
name
native-fips
description
Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS. Use when the user wants to enable FIPS compliance in a Go project, migrate from openssl-based FIPS to native Go FIPS, or when build configs contain GOEXPERIMENT=strictfipsruntime or openssl-based FIPS patterns. Triggers on: 'native FIPS', 'GOFIPS140', 'FIPS without openssl', 'enable FIPS', 'migrate FIPS', 'GOEXPERIMENT=strictfipsruntime', 'strictfipsruntime', 'fips140', 'Go FIPS module'.

Native FIPS

Configure a Go project to use Go's native FIPS 140 module (GOFIPS140). With CGO_ENABLED=0, this produces static binaries that no longer depend on the openssl RPM. Projects that require cgo should keep CGO_ENABLED=1 and adjust their FIPS setup accordingly. Works for both new projects and migrating existing openssl-based FIPS setups.

Reference

Build-time: GOFIPS140

Tells the Go compiler which FIPS 140 crypto module to embed into the binary.

ValueStatusML-KEMML-DSANotes
v1.0.0Validation completedYesNoValidated, stable
v1.26.0Module In Process (MIP)YesYesAdds ML-DSA + better entropy
latestAlias——Resolves to newest available module
certifiedAlias——Resolves to newest FIPS-certified module

Use certified in go build as it automatically resolves to the latest certified module (currently v1.0.0). Both modules support ML-KEM (post-quantum key encapsulation), so post-quantum key exchange is available without the old DEFAULT:PQ crypto-policies stage.

Build-time: GOEXPERIMENT=strictfipsruntime (downstream only)

The downstream golang-fips/go toolchain (used in RHEL/CentOS Go Toolset) provides GOEXPERIMENT=strictfipsruntime, which adds a startup check that panics if the binary's FIPS configuration is incompatible with the host environment. This is separate from GOFIPS140 — it provides fail-closed startup enforcement, not module selection.

When migrating a downstream build from the OpenSSL backend to native FIPS on 1.26+ builders, retain GOEXPERIMENT=strictfipsruntime and add -tags no_openssl to disable the OpenSSL backend. The 1.26+ builders imply GODEBUG=fips140=auto whenever the FIPS module is compiled in, so the binary works on both FIPS and non-FIPS hosts:

bash
CGO_ENABLED=0 GOFIPS140=v1.26.0 GOEXPERIMENT=strictfipsruntime go build -tags no_openssl ...

For upstream Go (which has no strictfipsruntime or OpenSSL backend):

bash
CGO_ENABLED=0 GOFIPS140=certified go build ...
Runtime: GODEBUG=fips140=<value>

Controls FIPS activation at runtime. You almost never need to set this explicitly. When a binary is built with GOFIPS140, the toolchain sets an appropriate default: upstream Go defaults to fips140=on, and the downstream golang-fips/go toolchain defaults (or will soon default) to fips140=auto. Only override this if you need behavior different from the toolchain default.

ValueBehaviorAvailability
fips140=autoFollow the host's FIPS setting (/proc/sys/crypto/fips_enabled)Downstream golang-fips/go only
fips140=onAlways enable FIPS, regardless of hostUpstream Go and downstream
fips140=onlyBest-effort FIPS-only mode — non-FIPS crypto calls may return an error or panic. May produce false positives/negatives. Test and assessment only — not for production.Upstream Go and downstream

Upstream Go (go.dev) supports off, on, and only. The auto value is provided by the downstream golang-fips/go toolchain.

Post-quantum cryptography (ML-KEM)

Go 1.24+ includes crypto/mlkem (FIPS 203) and crypto/tls uses X25519MLKEM768 by default for TLS connections. This means ML-KEM is built into the binary — no OS-level crypto-policies configuration is needed.

The old approach required a separate crypto-policies setup (via RPM or manual config) to enable DEFAULT:PQ. This configured system C libraries (OpenSSL, GnuTLS, NSS, etc.) by generating per-library config files in /etc/crypto-policies/back-ends/:

Backend fileLibrary
openssl.config / opensslcnf.configOpenSSL
gnutls.configGnuTLS
nss.configNSS (Mozilla)
openssh.config / opensshserver.configOpenSSH
java.configJava/OpenJDK
krb5.configKerberos
libssh.configlibssh

The :PQ subpolicy prepends hybrid ML-KEM groups at highest priority, adding X25519MLKEM768, P256-MLKEM768, P384-MLKEM1024 etc. to each backend in its native syntax.

Why this is unnecessary for Go binaries: A statically-compiled Go binary (CGO_ENABLED=0) with GOFIPS140 uses its own crypto/tls stack — it does not link against OpenSSL, GnuTLS, or NSS. OS-level crypto-policies back-end configs have zero effect on Go binaries. Such binaries have no runtime library dependencies, so they can run in minimal scratch-like images such as Hardened Images - Static.

Show full SKILL.md (301 more words)Show less

Verification with tls-scanner

The tls-scanner tool can verify endpoint TLS compliance on a running cluster — it connects to pod endpoints and checks their TLS configuration (protocol versions, cipher suites, and with PQC_CHECK=true, TLS 1.3 and ML-KEM readiness). It does not verify binary-level FIPS properties such as GOFIPS140 module embedding, runtime FIPS activation, or non-TLS cryptographic usage.

The tool source and documentation is at https://github.com/openshift/tls-scanner. The tls-scanner-run step ref is defined in the openshift/release step registry at ci-operator/step-registry/tls/scanner/run/.

Parameters
ParameterDefaultDescription
SCAN_NAMESPACE"" (all)Comma-separated namespaces to scan. Empty scans all namespaces.
PQC_CHECK"false"Set "true" to check post-quantum cryptography readiness (TLS 1.3 + ML-KEM support).
SCANNER_NAMESPACE""Namespace where the scanner pod is deployed. Empty creates a dedicated tls-scanner namespace.
SCAN_LIMIT_IPS""Max IPs to scan (empty/0 = no limit). Useful for smoke testing.
TLS_PROFILE_TYPE""Expected TLS profile type (Old, Intermediate, Modern). When set, overrides reading from APIServer/cluster.
TLS_SCANNER_CLUSTER_LABEL""HyperShift target: "management" or "guest". Empty scans via the step's KUBECONFIG.

Glossary

NameTypeValuesDescription
GOFIPS140Build env varcertified, latest, v1.0.0, v1.26.0Selects which FIPS 140 crypto module to embed. certified resolves to the latest validated module.
GOEXPERIMENT=strictfipsruntimeBuild env var(flag)Downstream only. Adds a startup panic if FIPS config is incompatible with the host.
CGO_ENABLEDBuild env var0, 10 produces a static binary with no C dependencies. 1 links against C libraries (needed if the project requires cgo).
-tags no_opensslBuild tag(flag)Disables the downstream OpenSSL crypto backend so the binary uses only Go's native FIPS module. Not needed for upstream Go.
fips140v1.26Synthesized build tag(automatic)Injected by the toolchain when GOFIPS140=v1.26.0 is set. Not user-specified.
GODEBUG=fips140Runtime env varauto, on, only, offControls FIPS activation at runtime. Rarely needs to be set — the toolchain picks the right default when built with GOFIPS140. auto is downstream only.

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/golang/skills/native-fips of openshift-eng/ai-helpers.

Open the folder on GitHubat commit a627176

Compare with similar skills

Native Fips next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Native Fips compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Native Fips this skillopenshift-eng/ai-helpers120—~2kAutomated safety check: PassApache-2.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp114—~847Automated safety check: PassMIT
Crypto Analysishypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2201 repos~3.3kAutomated safety check: NotesCustom licence

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    114 GitHub stars~847 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    388 GitHub stars~2.2k tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 25 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    220 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.5k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Native Fips

What does Native Fips do?

Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS. Native Fips is an agent skill from openshift-eng/ai-helpers. Configure Go projects to use Go's native FIPS 140 module instead of openssl-based FIPS.

When should I use Native Fips?

Native Fips fits situations like: the user wants to enable FIPS compliance in a Go project; migrate from openssl-based FIPS to native Go FIPS; build configs contain GOEXPERIMENT=strictfipsruntime; openssl-based FIPS patterns.

How do I install Native Fips in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill native-fips -a claude-code`. Or copy the skill folder (plugins/golang/skills/native-fips in openshift-eng/ai-helpers) into .claude/skills/native-fips in your project. Claude Code loads it when a task matches its description.

How do I install Native Fips in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill native-fips -a codex`. Or copy the skill folder (plugins/golang/skills/native-fips in openshift-eng/ai-helpers) into .agents/skills/native-fips in your project. Codex loads it when a task matches its description.

Can I use Native Fips in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill native-fips -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/native-fips, .gemini/skills/native-fips, .github/skills/native-fips and .opencode/skills/native-fips in your project.

What does Native Fips need to run?

Going by SKILL.md and its folder, Native Fips needs the command-line tools its instructions call (go).

Does Native Fips access the network?

SKILL.md names 3 domains. As links in the text: github.com, gitlab.com and images.redhat.com. This is read from the text; nothing was executed.

Is Native Fips safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Native Fips use?

Native Fips is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Native Fips use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Native Fips?

Skills that share tags, products or a category with Native Fips: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 114 stars), Crypto Analysis (hypnguyen1209/offensive-claude, 388 stars) and Security Review (valory-xyz/open-autonomy, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Native Fips?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.