Code Security Audit
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.
$ npx skills add SpecterOps/skills --skill go-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SpecterOps/skills go-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/go-review/skills/go-review .claude/skills/go-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "go-review" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-review into .claude/skills/go-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "go-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SpecterOps/skills --skill go-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SpecterOps/skills go-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/go-review/skills/go-review .agents/skills/go-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "go-review" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-review into .agents/skills/go-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "go-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SpecterOps/skills --skill go-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SpecterOps/skills go-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/go-review/skills/go-review .cursor/skills/go-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "go-review" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-review into .cursor/skills/go-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "go-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SpecterOps/skills.git --path plugins/go-review/skills/go-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SpecterOps/skills --skill go-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SpecterOps/skills go-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/go-review/skills/go-review .gemini/skills/go-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "go-review" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-review into .gemini/skills/go-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "go-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SpecterOps/skills go-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SpecterOps/skills --skill go-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/go-review/skills/go-review .github/skills/go-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "go-review" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-review into .github/skills/go-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "go-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SpecterOps/skills --skill go-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SpecterOps/skills go-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/go-review/skills/go-review .opencode/skills/go-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "go-review" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/go-review/skills/go-review into .opencode/skills/go-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "go-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
go-reviewPerforms security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.
Go Review is an agent skill from SpecterOps/skills. Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. Covers authentication and authorization, request parsing, SSRF, SQL and command injection, templates and filesystems, crypto/session handling, concurrency, and unsafe/cgo edges.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Security review, gRPC and Protobuf and Web application vulnerabilities. It works with gRPC and SQL. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Go Review loads about 2.1k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 898 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 898 words, ~2,116 tokens.
.claude/skills/go-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Runs in the main conversation. The orchestrator builds a Go inventory, selects review clusters, delegates or sequentially executes their worker protocols, validates artifacts, then runs dedup and FP/severity judges.
Collect these once if they are not explicit. Do not ask for a worker model by default; inherit the current session/client model. Honor a model only when the user explicitly names one that the client makes available.
| Parameter | Values |
|---|---|
threat_model | REMOTE, LOCAL_UNPRIVILEGED, BOTH |
severity_filter | all, medium, high |
scope_subpath | optional; defaults to . |
Resolve the directory containing prompts/clusters/manifest.json and
go_inventory.go from ${CODEX_PLUGIN_ROOT},
${CLAUDE_PLUGIN_ROOT}, or the installed location of this skill. Do not scan a
user's home directory. Abort with an actionable error if no root resolves.
Require Go 1.22 or newer. The inventory is implemented with the Go standard library, uses the locally installed toolchain without automatic downloads, and does not fetch the target's module dependencies. Source using syntax newer than the installed Go version can still fail to parse.
Choose output_dir as .go-review-results/<UTC timestamp>/, or use an external
location requested by the user. Create it and run the inventory portably with:
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/prepare_review.py" \
--repo-root "." \
--scope-subpath "${scope_subpath}" \
--output-dir "${output_dir}"Abort only if the inventory reports zero .go files. If has_service=false,
skip the service-boundary and request-input clusters and continue with any
other detected package capabilities.
The inventory schema remains at version 1. Its implementation uses Go syntax trees for imports, declarations, calls, routes, goroutines, and channel types; do not replace these results with text searches over source files.
This is conservative syntax analysis, not type or SSA analysis. It inventories
all matching non-test .go files regardless of build tags, crosses nested Go
modules within scope, and reports the review root's module in the top-level
module field. Capability heuristics can still over-select a cluster; workers
must verify reachability and data flow from source evidence.
Read go-inventory.json and write context.md with YAML frontmatter:
threat_modelseverity_filterscope_subpathgo_file_countpackage_countoutput_dirThe body must summarize:
Run:
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/build_run_plan.py" \
--plugin-root "${GO_REVIEW_PLUGIN_ROOT}" \
--output-dir "${output_dir}" \
--threat-model "${threat_model}" \
--severity-filter "${severity_filter}" \
--scope-subpath "${scope_subpath}" \
--context-roots "." \
--has-service "${has_service}" \
--has-outbound-http "${has_outbound_http}" \
--has-sql "${has_sql}" \
--has-exec "${has_exec}" \
--has-fs-archive "${has_fs_archive}" \
--has-template "${has_template}" \
--has-crypto-auth "${has_crypto_auth}" \
--has-concurrency "${has_concurrency}" \
--has-unsafe-cgo "${has_unsafe_cgo}"Read plan.json; do not manually re-derive cluster selection.
The portable contracts are the bundled protocol files
agents/go-review-worker.md, agents/go-review-dedup-judge.md, and
agents/go-review-fp-judge.md. Do not assume those filenames are registered as
callable agent names. Read the relevant protocol and pass it with each rendered
prompt to the client-provided delegation mechanism. If delegation is not
available, execute each assignment sequentially in the main session while
preserving the same artifact contract.
Execution rules:
run_in_background=trueIf plan.json contains zero workers, create an empty findings-index.txt, note
that no capability-gated clusters were selected in run-summary.md, and proceed
to reporting. Do not treat an ordinary package with no selected clusters as a
workflow failure.
For each completed worker, run:
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/validate_artifacts.py" \
"${output_dir}/plan.json" \
--worker "worker-N" \
--claimed-count "worker-N=<count>"After all workers complete, reconcile shards and initialize deterministic empty reports when applicable:
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/finalize_run.py" "${output_dir}"This builds findings-index.txt from the union of worker shards and
findings/*.md, retains orphan findings, and records incomplete shards in
run-summary.md; do not silently drop a finding because a worker crashed after
writing it.
Run the bundled dedup protocol, then the bundled FP protocol, each with
output_dir in the prompt. The FP judge also receives the absolute path to
generate_sarif.py. Use delegated workers when
available or execute these protocols sequentially in the main session.
Always run the SARIF safety net:
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/generate_sarif.py" "${output_dir}"Return REPORT.md, REPORT.sarif, go-inventory.json, and run-summary.md.
go-inventory.json exists and reports at least one Go filefindings-index.txt exists even for zero findingsdedup-summary.md, fp-summary.md, REPORT.md, and REPORT.sarif existrun-summary.md.go-review-results/ may contain source excerpts, suspected vulnerabilities,
and absolute local paths. Treat it as sensitive assessment data. Before sharing
or committing it, review and redact the contents. Recommend that users ignore
the directory in the target repository or choose an external output location,
but do not modify .gitignore without permission.
The implementation approach and security-review taxonomy are annotated in references/provenance.md. Treat those sources as guidance; findings still require evidence from the repository under review.
© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in plugins/go-review/skills/go-review of SpecterOps/skills.
Open the folder on GitHubat commit e655f93
Go Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Go Review this skillSpecterOps/skills | 706 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Code Security AuditProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Security Reviewliuyanghejerry/Clausura | 204 | — | ~106 | Automated safety check: Pass | MIT | |
| Static Vulnerability DetectorArabelaTso/Skills-4-SE | 253 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| File To Codejeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | |
| API Security ReviewOWASP/secure-agent-playbook | 188 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 |
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
liuyanghejerry/Clausura
检查 SQL 注入、XSS、硬编码密钥
ArabelaTso/Skills-4-SE
Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…
jeremylongshore/tons-of-skills-marketplace
Generates production-ready code from file specifications such as CSV files, JSON schemas, SQL DDL, protobuf definitions, or requirements documents.
OWASP/secure-agent-playbook
Comprehensive API security review against OWASP API Security Top 10 (2023).
SnailSploit/Claude-Red
Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.
SpecterOps/skills
Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.
SpecterOps/skills
A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…
SpecterOps/skills
Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…
SpecterOps/skills
A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.
SpecterOps/skills
Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.
SpecterOps/skills
Perform OSINT and external reconnaissance for approved targets.
Categories
Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. Go Review is an agent skill from SpecterOps/skills. Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.
Go Review fits situations like: tasks that involve Security review; tasks that involve gRPC and Protobuf; tasks that involve Web application vulnerabilities.
Run `npx skills add SpecterOps/skills --skill go-review -a claude-code`. Or copy the skill folder (plugins/go-review/skills/go-review in SpecterOps/skills) into .claude/skills/go-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SpecterOps/skills --skill go-review -a codex`. Or copy the skill folder (plugins/go-review/skills/go-review in SpecterOps/skills) into .agents/skills/go-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill go-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/go-review, .gemini/skills/go-review, .github/skills/go-review and .opencode/skills/go-review in your project.
Going by SKILL.md and its folder, Go Review needs the command-line tools its instructions call (python3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Go Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Go Review: Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Security Review (liuyanghejerry/Clausura, 204 stars), Static Vulnerability Detector (ArabelaTso/Skills-4-SE, 253 stars) and File To Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 706 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.
Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.