Agent skill

Golang Rules

by softspark in softspark/ai-toolkit

Go coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

Apache-2.0Auto-check passedSecurity

Install Golang Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill golang-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit golang-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/golang-rules .claude/skills/golang-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
golang-rules
GitHub stars
179
Token cost
~3k tokens
SKILL.md length
1,440 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Go coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

  • Security work in your project
  • SKILL.md covers Naming, Packages, Functions and Error Handling, plus 21 more sections
  • Calls go; needs SECRET_KEY

What it does

Golang Rules is an agent skill from softspark/ai-toolkit. Go coding rules: style, patterns, security, testing. Triggers: .go, go.mod, go.sum, Gin, Echo, Gorilla, testing, gofmt.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. It works with Go. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/golang-rules”

Requirements

  • A credential in SECRET_KEY
  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit e40ed87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Golang Rules loads about 3k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 1,440 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit e40ed87, republished under its Apache-2.0 licence (© softspark). 1,440 words, ~2,953 tokens.

Download SKILL.mdSave it as .claude/skills/golang-rules/SKILL.md (or your agent's skills folder).
name
golang-rules
description
Go coding rules: style, patterns, security, testing. Triggers: .go, go.mod, go.sum, Gin, Echo, Gorilla, testing, gofmt.
allowed-tools
Read
effort
medium
user-invocable
false

Go Rules

These rules come from app/rules/golang/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in Go. Apply them when writing or reviewing Go code.

Go Coding Style

Naming

  • MixedCaps/mixedCaps only. No underscores in Go names (except test functions).
  • Exported: PascalCase. Unexported: camelCase. Acronyms: HTTPClient, userID.
  • Short variable names in small scopes: i, r, w, ctx, err.
  • Descriptive names in larger scopes: userRepository, requestTimeout.
  • Package names: short, lowercase, singular (auth, user, not utils, helpers).

Packages

  • One package per directory. Package name = directory name.
  • Avoid util, common, helpers packages. Name by what it provides.
  • Keep package APIs small. Export only what consumers need.
  • Use internal/ directory for packages not meant for external consumption.

Functions

  • Accept interfaces, return structs.
  • First parameter ctx context.Context if the function does I/O or may be cancelled.
  • Return (result, error) tuple. Error is always last return value.
  • Use named return values only for documentation, not for naked returns.
  • Keep functions short. If >40 lines, consider splitting.

Error Handling

  • Always check errors. Never use _ to discard errors silently.
  • Wrap errors with context: fmt.Errorf("fetching user %s: %w", id, err).
  • Use sentinel errors (var ErrNotFound = errors.New(...)) for expected conditions.
  • Use errors.Is() and errors.As() for error checking, not type assertions.

Formatting

  • Use gofmt / goimports. No formatting debates in Go.
  • Use golangci-lint with a .golangci.yml config in CI.
  • Use go vet as minimum static analysis.

Struct Design

  • Use struct embedding for composition, not inheritance.
  • Prefer value receivers for small structs, pointer receivers for large or mutable.
  • Be consistent: all methods on a type use the same receiver type.
  • Use struct literals with field names: User{Name: "Ada", Age: 30}.

Concurrency

  • Do not start goroutines without a plan to stop them.
  • Use sync.WaitGroup or errgroup.Group to coordinate goroutines.
  • Use channels for communication, mutexes for state protection.
  • Prefer context.Context for cancellation and timeouts over manual signaling.

Go Frameworks

Standard Library HTTP

  • Use http.NewServeMux() (Go 1.22+ with method patterns) for simple APIs.
  • Use http.HandlerFunc for handlers. Compose with middleware pattern.
  • Use context.Context from r.Context() in all handlers.
  • Use http.TimeoutHandler to prevent slow handlers from hanging.

Chi / Gorilla Mux

  • Use Chi for routing with middleware chains and URL params.
  • Use chi.URLParam(r, "id") to extract path parameters.
  • Use middleware groups: r.Group(func(r chi.Router) { r.Use(authMiddleware) }).
  • Prefer Chi over Gorilla Mux (Gorilla was archived, Chi actively maintained).

Gin / Echo

  • Use Gin for high-performance APIs with built-in validation.
  • Use binding tags: binding:"required,email" on struct fields.
  • Use middleware for cross-cutting: logging, recovery, CORS, auth.
  • Use c.ShouldBindJSON() over c.BindJSON() to handle errors yourself.

GORM / sqlx / pgx

  • Use sqlx for SQL-first with struct scanning (lightweight).
  • Use pgx directly for PostgreSQL-specific features and performance.
  • Use GORM only when rapid prototyping outweighs SQL control.
  • Always use prepared statements or parameterized queries.
  • Use sqlx.In() for dynamic IN clauses safely.

gRPC

  • Define services in .proto files. Generate Go code with protoc.
  • Use interceptors for auth, logging, and tracing (equivalent to middleware).
  • Use deadlines (context timeout) on every RPC call.
  • Use streaming RPCs for real-time data, unary for request-response.

Configuration

  • Use envconfig or viper for configuration from env/files.
  • Use struct tags for env mapping: envconfig:"DATABASE_URL".
  • Validate config at startup. Fail fast on invalid configuration.
  • Use flag package for CLI arguments in tools and utilities.

Observability

  • Use slog (Go 1.21+) for structured logging. Replace log package.
  • Use OpenTelemetry for distributed tracing and metrics.
  • Export metrics via Prometheus endpoint.
  • Use pprof for CPU and memory profiling in development.

Project Layout

  • Follow Standard Go Project Layout: cmd/, internal/, pkg/.
  • Entry points in cmd/appname/main.go.
  • Business logic in internal/. Shared libraries in pkg/.
  • Use Makefile for common tasks: build, test, lint, run.

Go Patterns

Error Handling

  • Wrap errors with context at each call site: fmt.Errorf("loading config: %w", err).
  • Define domain error types with errors.New() or custom error structs.
  • Use errors.Is() for sentinel errors, errors.As() for typed errors.
  • Return errors, do not panic. Reserve panic for truly unrecoverable states.
  • Handle errors immediately after the call. No deferred error checking.

Concurrency

  • Use errgroup.Group for concurrent operations that may fail.
  • Use sync.Once for one-time initialization (singleton pattern).
  • Use sync.Map only for append-mostly maps with concurrent access.
  • Use buffered channels as semaphores: sem := make(chan struct{}, maxConcurrency).
  • Prefer context.WithTimeout over manual timers for deadline management.

Interface Design

  • Keep interfaces small: 1-3 methods. Compose larger interfaces from smaller ones.
  • Define interfaces where they are consumed, not where they are implemented.
  • Use io.Reader, io.Writer, fmt.Stringer and standard interfaces where applicable.
  • Avoid returning interfaces from functions. Return concrete types.

Options Pattern

  • Use functional options for constructors with many optional parameters.
  • Pattern: func WithTimeout(d time.Duration) Option { return func(c *Client) { c.timeout = d } }.
  • Provide sensible defaults. Options override defaults.
  • Use Option type alias: type Option func(*Config).

Dependency Injection

  • Pass dependencies through constructor functions, not global variables.
  • Accept interfaces in constructors: func NewService(repo UserRepo) *Service.
  • Use wire or manual wiring in main() for dependency graph.
  • Avoid init() functions for anything other than simple registration.

Resource Management

  • Use defer for cleanup immediately after acquiring a resource.
  • Use context.Context for cancellation propagation across goroutines.
  • Close channels from the sender side, never the receiver.
  • Use sync.Pool for frequently allocated temporary objects (buffers).

Anti-Patterns

  • Global mutable state: use dependency injection instead.
  • interface{} / any everywhere: use generics (Go 1.18+) or specific types.
  • Goroutine leaks: always ensure goroutines can exit.
  • Ignoring context.Context: propagate it through all I/O paths.
  • Large interfaces: split into focused, composable pieces.
Show full SKILL.md (561 more words)Show less

Go Security

Input Validation

  • Validate all input at API boundaries. Use struct tags or manual validation.
  • Use validator package for struct validation: validate:"required,email".
  • Parse and validate numeric IDs: strconv.Atoi() with error checking.
  • Limit request body size: http.MaxBytesReader(w, r.Body, maxBytes).

SQL Injection

  • Always use parameterized queries: db.Query("SELECT * FROM users WHERE id = $1", id).
  • Never concatenate user input into SQL strings.
  • Use sqlx.In() for safe dynamic IN clauses.
  • Use ORM query builders (GORM, Ent) for dynamic query construction.

Command Injection

  • Use exec.Command("binary", args...) with separate arguments, not shell strings.
  • Never use exec.Command("sh", "-c", userInput).
  • Validate and sanitize file paths against traversal attacks.
  • Use filepath.Clean() and verify paths are within allowed directories.

Cryptography

  • Use crypto/rand for random values, never math/rand for security.
  • Use bcrypt or argon2 for password hashing: golang.org/x/crypto/bcrypt.
  • Use crypto/subtle.ConstantTimeCompare() for timing-safe comparisons.
  • Use crypto/tls with tls.Config{MinVersion: tls.VersionTLS12}.

Secrets

  • Load secrets from environment variables: os.Getenv("SECRET_KEY").
  • Never hardcode secrets, tokens, or API keys in source code.
  • Use go-envconfig or similar for validated env var loading.
  • Use Go build tags or ldflags for build-time configuration.

HTTP Security

  • Set ReadTimeout, WriteTimeout, IdleTimeout on http.Server.
  • Use helmet-equivalent headers: HSTS, X-Content-Type-Options, X-Frame-Options.
  • Implement rate limiting with golang.org/x/time/rate or middleware.
  • Use net/http with TLS. Never serve production HTTP without encryption.

Concurrency Safety

  • Use sync.Mutex or sync.RWMutex for shared mutable state.
  • Run go test -race in CI to detect data races.
  • Avoid shared state where possible. Prefer channels for communication.
  • Use atomic package for simple counters and flags.

Dependencies

  • Run govulncheck ./... in CI to check for known vulnerabilities.
  • Use go mod tidy to remove unused dependencies.
  • Pin dependencies via go.sum. Review dependency changes in PRs.
  • Audit transitive dependencies. Use go mod graph to inspect the tree.

Error Information Disclosure

  • Never expose internal error messages to clients.
  • Log detailed errors server-side, return generic messages to clients.
  • Use error codes for machine-readable error classification.
  • Do not include stack traces in production API responses.

Go Testing

Framework

  • Use the standard testing package. No external test frameworks required.
  • Use testify/assert and testify/require for readable assertions.
  • Use testify/mock or mockgen for generating mocks.
  • Use go test -race in CI to detect data races.

File Naming

  • Test files: *_test.go in the same package.
  • Black-box tests: use package foo_test to test only exported API.
  • White-box tests: use package foo to test internals.
  • Test helpers: testutil_test.go or testdata/ directory.

Table-Driven Tests

  • Use table-driven tests for functions with multiple input/output cases.
  • Name each case: {name: "empty input returns error", input: "", wantErr: true}.
  • Use t.Run(tc.name, func(t *testing.T) { ... }) for subtests.
  • Use t.Parallel() in subtests when tests are independent.

Test Helpers

  • Use t.Helper() in helper functions for correct line reporting.
  • Use t.Cleanup() for teardown instead of defer in test functions.
  • Use testing.TB interface to share helpers between tests and benchmarks.
  • Use testdata/ directory for test fixtures (excluded from build).

Mocking

  • Define interfaces at the consumer, not the provider.
  • Use mockgen to auto-generate mocks from interfaces.
  • Use httptest.NewServer() for HTTP integration tests.
  • Use httptest.NewRecorder() for handler unit tests.

Integration Tests

  • Use build tags: //go:build integration to separate from unit tests.
  • Use testcontainers-go for database/service containers in tests.
  • Use t.Setenv() (Go 1.17+) for environment variable testing.

Benchmarks

  • Use func BenchmarkXxx(b *testing.B) with b.N loop.
  • Use b.ResetTimer() after expensive setup.
  • Use b.ReportAllocs() to track allocations.
  • Run: go test -bench=. -benchmem.

Coverage

  • Run: go test -coverprofile=coverage.out ./....
  • View: go tool cover -html=coverage.out.
  • Set minimum coverage threshold in CI.
  • Focus coverage on business logic, not generated code.

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/golang-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit e40ed87

Compare with similar skills

Golang Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Golang Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Golang Rules this skillsoftspark/ai-toolkit179—~3kAutomated safety check: PassApache-2.0
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0
Cosmos Vulnerability Scannertrailofbits/skills7.4k—~2.7kAutomated safety check: PassCC-BY-SA-4.0
Go Helpershepherdjerred/monorepo112—~1.7kAutomated safety check: PassGPL-3.0
Dependency Auditorpilinux/gorest506—~273Automated safety check: PassMIT
Go Pedantrychromedp/chromedp13k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed
  • Official

    Scans Cosmos SDK modules and CosmWasm contracts for consensus-critical flaws that can halt a chain, lose funds or diverge state, using parallel scanning agents.

    7.4k GitHub stars~2.7k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Go Helper

    shepherdjerred/monorepo

    Current Go development guidance for modules, toolchains, workspaces, testing, fuzzing, concurrency, profiling, security, and Go tooling.

    112 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Dependency Auditor

    pilinux/gorest

    Inspect Go module dependencies, detect outdated or vulnerable modules, and recommend safe updates or pinning strategies.

    506 GitHub stars~273 tokensUpdated 14 days ago
    DatabasesAuto-check passed
  • Go Pedantry

    chromedp/chromedp

    This skill should be used when the user is writing Go code and needs guidance on Go-specific pedantry: error wrapping with fmt.Errorf and %w, interface design (accept interfaces return structs)…

    13k GitHub stars~3.7k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Golang Pro

    antoniopaya22/go-rest-template

    Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…

    172 GitHub starsUsed in 3 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Golang Rules

What does Golang Rules do?

Go coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Golang Rules is an agent skill from softspark/ai-toolkit. Go coding rules: style, patterns, security, testing.

When should I use Golang Rules?

Golang Rules fits situations like: security work in your project.

How do I install Golang Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill golang-rules -a claude-code`. Or copy the skill folder (app/skills/golang-rules in softspark/ai-toolkit) into .claude/skills/golang-rules in your project. Claude Code loads it when a task matches its description.

How do I install Golang Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill golang-rules -a codex`. Or copy the skill folder (app/skills/golang-rules in softspark/ai-toolkit) into .agents/skills/golang-rules in your project. Codex loads it when a task matches its description.

Can I use Golang Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill golang-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/golang-rules, .gemini/skills/golang-rules, .github/skills/golang-rules and .opencode/skills/golang-rules in your project.

What does Golang Rules need to run?

Going by SKILL.md and its folder, Golang Rules needs the command-line tools its instructions call (go) and credentials named SECRET_KEY. Our summary lists: A credential in SECRET_KEY. Its frontmatter pre-approves these tools: Read.

Does Golang Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Golang Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Golang Rules use?

Golang Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Golang Rules use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Golang Rules?

Skills that share tags, products or a category with Golang Rules: Snapshot (boostsecurityio/poutine, 523 stars), Cosmos Vulnerability Scanner (trailofbits/skills, 7.4k stars), Go Helper (shepherdjerred/monorepo, 112 stars) and Dependency Auditor (pilinux/gorest, 506 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Golang Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 8, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.