Snapshot
boostsecurityio/poutine
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
Go coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.
$ npx skills add softspark/ai-toolkit --skill golang-rules -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install softspark/ai-toolkit golang-rules --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/golang-rules .claude/skills/golang-rules && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "golang-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rules into .claude/skills/golang-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-rules", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rulesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add softspark/ai-toolkit --skill golang-rules -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install softspark/ai-toolkit golang-rules --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/app/skills/golang-rules .agents/skills/golang-rules && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "golang-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rules into .agents/skills/golang-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-rules", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill golang-rules -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install softspark/ai-toolkit golang-rules --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/app/skills/golang-rules .cursor/skills/golang-rules && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "golang-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rules into .cursor/skills/golang-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-rules", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/softspark/ai-toolkit.git --path app/skills/golang-rules--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add softspark/ai-toolkit --skill golang-rules -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install softspark/ai-toolkit golang-rules --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/app/skills/golang-rules .gemini/skills/golang-rules && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "golang-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rules into .gemini/skills/golang-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-rules", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install softspark/ai-toolkit golang-rulesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add softspark/ai-toolkit --skill golang-rules -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/app/skills/golang-rules .github/skills/golang-rules && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "golang-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rules into .github/skills/golang-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-rules", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill golang-rules -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install softspark/ai-toolkit golang-rules --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/app/skills/golang-rules .opencode/skills/golang-rules && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "golang-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/golang-rules into .opencode/skills/golang-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-rules", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
golang-rulesGo coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.
Golang Rules is an agent skill from softspark/ai-toolkit. Go coding rules: style, patterns, security, testing. Triggers: .go, go.mod, go.sum, Gin, Echo, Gorilla, testing, gofmt.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. It works with Go. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit e40ed87. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Golang Rules loads about 3k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 1,440 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from softspark/ai-toolkit at commit e40ed87, republished under its Apache-2.0 licence (© softspark). 1,440 words, ~2,953 tokens.
.claude/skills/golang-rules/SKILL.md (or your agent's skills folder).These rules come from app/rules/golang/ in ai-toolkit. They cover
the project's standards for coding style, frameworks, patterns,
security, and testing in Go. Apply them when writing or
reviewing Go code.
PascalCase. Unexported: camelCase. Acronyms: HTTPClient, userID.i, r, w, ctx, err.userRepository, requestTimeout.auth, user, not utils, helpers).util, common, helpers packages. Name by what it provides.internal/ directory for packages not meant for external consumption.ctx context.Context if the function does I/O or may be cancelled.(result, error) tuple. Error is always last return value._ to discard errors silently.fmt.Errorf("fetching user %s: %w", id, err).var ErrNotFound = errors.New(...)) for expected conditions.errors.Is() and errors.As() for error checking, not type assertions.gofmt / goimports. No formatting debates in Go.golangci-lint with a .golangci.yml config in CI.go vet as minimum static analysis.User{Name: "Ada", Age: 30}.sync.WaitGroup or errgroup.Group to coordinate goroutines.context.Context for cancellation and timeouts over manual signaling.http.NewServeMux() (Go 1.22+ with method patterns) for simple APIs.http.HandlerFunc for handlers. Compose with middleware pattern.context.Context from r.Context() in all handlers.http.TimeoutHandler to prevent slow handlers from hanging.chi.URLParam(r, "id") to extract path parameters.r.Group(func(r chi.Router) { r.Use(authMiddleware) }).binding:"required,email" on struct fields.c.ShouldBindJSON() over c.BindJSON() to handle errors yourself.sqlx for SQL-first with struct scanning (lightweight).pgx directly for PostgreSQL-specific features and performance.sqlx.In() for dynamic IN clauses safely..proto files. Generate Go code with protoc.envconfig or viper for configuration from env/files.envconfig:"DATABASE_URL".flag package for CLI arguments in tools and utilities.slog (Go 1.21+) for structured logging. Replace log package.pprof for CPU and memory profiling in development.cmd/, internal/, pkg/.cmd/appname/main.go.internal/. Shared libraries in pkg/.Makefile for common tasks: build, test, lint, run.fmt.Errorf("loading config: %w", err).errors.New() or custom error structs.errors.Is() for sentinel errors, errors.As() for typed errors.panic for truly unrecoverable states.errgroup.Group for concurrent operations that may fail.sync.Once for one-time initialization (singleton pattern).sync.Map only for append-mostly maps with concurrent access.sem := make(chan struct{}, maxConcurrency).context.WithTimeout over manual timers for deadline management.io.Reader, io.Writer, fmt.Stringer and standard interfaces where applicable.func WithTimeout(d time.Duration) Option { return func(c *Client) { c.timeout = d } }.Option type alias: type Option func(*Config).func NewService(repo UserRepo) *Service.wire or manual wiring in main() for dependency graph.defer for cleanup immediately after acquiring a resource.context.Context for cancellation propagation across goroutines.sync.Pool for frequently allocated temporary objects (buffers).interface{} / any everywhere: use generics (Go 1.18+) or specific types.context.Context: propagate it through all I/O paths.validator package for struct validation: validate:"required,email".strconv.Atoi() with error checking.http.MaxBytesReader(w, r.Body, maxBytes).db.Query("SELECT * FROM users WHERE id = $1", id).sqlx.In() for safe dynamic IN clauses.exec.Command("binary", args...) with separate arguments, not shell strings.exec.Command("sh", "-c", userInput).filepath.Clean() and verify paths are within allowed directories.crypto/rand for random values, never math/rand for security.bcrypt or argon2 for password hashing: golang.org/x/crypto/bcrypt.crypto/subtle.ConstantTimeCompare() for timing-safe comparisons.crypto/tls with tls.Config{MinVersion: tls.VersionTLS12}.os.Getenv("SECRET_KEY").go-envconfig or similar for validated env var loading.ReadTimeout, WriteTimeout, IdleTimeout on http.Server.helmet-equivalent headers: HSTS, X-Content-Type-Options, X-Frame-Options.golang.org/x/time/rate or middleware.net/http with TLS. Never serve production HTTP without encryption.sync.Mutex or sync.RWMutex for shared mutable state.go test -race in CI to detect data races.atomic package for simple counters and flags.govulncheck ./... in CI to check for known vulnerabilities.go mod tidy to remove unused dependencies.go.sum. Review dependency changes in PRs.go mod graph to inspect the tree.testing package. No external test frameworks required.testify/assert and testify/require for readable assertions.testify/mock or mockgen for generating mocks.go test -race in CI to detect data races.*_test.go in the same package.package foo_test to test only exported API.package foo to test internals.testutil_test.go or testdata/ directory.{name: "empty input returns error", input: "", wantErr: true}.t.Run(tc.name, func(t *testing.T) { ... }) for subtests.t.Parallel() in subtests when tests are independent.t.Helper() in helper functions for correct line reporting.t.Cleanup() for teardown instead of defer in test functions.testing.TB interface to share helpers between tests and benchmarks.testdata/ directory for test fixtures (excluded from build).mockgen to auto-generate mocks from interfaces.httptest.NewServer() for HTTP integration tests.httptest.NewRecorder() for handler unit tests.//go:build integration to separate from unit tests.testcontainers-go for database/service containers in tests.t.Setenv() (Go 1.17+) for environment variable testing.func BenchmarkXxx(b *testing.B) with b.N loop.b.ResetTimer() after expensive setup.b.ReportAllocs() to track allocations.go test -bench=. -benchmem.go test -coverprofile=coverage.out ./....go tool cover -html=coverage.out.© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in app/skills/golang-rules of softspark/ai-toolkit.
Open the folder on GitHubat commit e40ed87
Golang Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Golang Rules this skillsoftspark/ai-toolkit | 179 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Snapshotboostsecurityio/poutine | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | |
| Cosmos Vulnerability Scannertrailofbits/skills | 7.4k | — | ~2.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Go Helpershepherdjerred/monorepo | 112 | — | ~1.7k | Automated safety check: Pass | GPL-3.0 | |
| Dependency Auditorpilinux/gorest | 506 | — | ~273 | Automated safety check: Pass | MIT | |
| Go Pedantrychromedp/chromedp | 13k | — | ~3.7k | Automated safety check: Pass | MIT |
boostsecurityio/poutine
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
trailofbits/skills
Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.
shepherdjerred/monorepo
Current Go development guidance for modules, toolchains, workspaces, testing, fuzzing, concurrency, profiling, security, and Go tooling.
pilinux/gorest
Inspect Go module dependencies, detect outdated or vulnerable modules, and recommend safe updates or pinning strategies.
chromedp/chromedp
This skill should be used when the user is writing Go code and needs guidance on Go-specific pedantry: error wrapping with fmt.Errorf and %w, interface design (accept interfaces return structs)…
antoniopaya22/go-rest-template
Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…
softspark/ai-toolkit
Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.
softspark/ai-toolkit
Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Analyzes code quality, complexity, patterns across codebase.
softspark/ai-toolkit
Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.
softspark/ai-toolkit
Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).
Works with
Categories
Go coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Golang Rules is an agent skill from softspark/ai-toolkit. Go coding rules: style, patterns, security, testing.
Golang Rules fits situations like: security work in your project.
Run `npx skills add softspark/ai-toolkit --skill golang-rules -a claude-code`. Or copy the skill folder (app/skills/golang-rules in softspark/ai-toolkit) into .claude/skills/golang-rules in your project. Claude Code loads it when a task matches its description.
Run `npx skills add softspark/ai-toolkit --skill golang-rules -a codex`. Or copy the skill folder (app/skills/golang-rules in softspark/ai-toolkit) into .agents/skills/golang-rules in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill golang-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/golang-rules, .gemini/skills/golang-rules, .github/skills/golang-rules and .opencode/skills/golang-rules in your project.
Going by SKILL.md and its folder, Golang Rules needs the command-line tools its instructions call (go) and credentials named SECRET_KEY. Our summary lists: A credential in SECRET_KEY. Its frontmatter pre-approves these tools: Read.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Golang Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Golang Rules: Snapshot (boostsecurityio/poutine, 523 stars), Cosmos Vulnerability Scanner (trailofbits/skills, 7.4k stars), Go Helper (shepherdjerred/monorepo, 112 stars) and Dependency Auditor (pilinux/gorest, 506 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 8, 2026.
Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.