Agent skill

Go Review

by SpecterOps in SpecterOps/skills

Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.

Apache-2.0Auto-check passedSecurity

Install Go Review

skills CLI
$ npx skills add SpecterOps/skills --skill go-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills go-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/go-review/skills/go-review .claude/skills/go-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
go-review
GitHub stars
706
Token cost
~2.1k tokens
SKILL.md length
898 words
Files
2
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.

  • Works in 7 steps: Resolve Plugin Root → Build Go Inventory → Write Context → …
  • Tasks that involve Security review
  • SKILL.md covers When to Use, When NOT to Use, Rationalizations to Reject and Required Inputs, plus 4 more sections
  • Calls python3

What it does

Go Review is an agent skill from SpecterOps/skills. Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. Covers authentication and authorization, request parsing, SSRF, SQL and command injection, templates and filesystems, crypto/session handling, concurrency, and unsafe/cgo edges.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Security review, gRPC and Protobuf and Web application vulnerabilities. It works with gRPC and SQL. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve gRPC and Protobuf
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “Use the go-review skill to perform security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and…”
  • “/go-review”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Resolve Plugin Root
  2. Build Go Inventory
  3. Write Context
  4. Build Deterministic Run Plan
  5. Run Worker Protocols
  6. Validate Worker Artifacts
  7. Judges and Reports

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Go Review loads about 2.1k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 898 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 898 words, ~2,116 tokens.

Download SKILL.mdSave it as .claude/skills/go-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
go-review
description
Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. Covers authentication and authorization, request parsing, SSRF, SQL and command injection, templates and filesystems, crypto/session handling, concurrency, and unsafe/cgo edges.

Go Security Review

Runs in the main conversation. The orchestrator builds a Go inventory, selects review clusters, delegates or sequentially executes their worker protocols, validates artifacts, then runs dedup and FP/severity judges.

When to Use

  • Auditing Go HTTP, gRPC, GraphQL, or RPC services
  • Reviewing backend APIs, daemons, gateways, proxies, or agents with network exposure
  • Investigating authorization, SSRF, SQL, template, filesystem, concurrency, or cgo risk
  • Reviewing Go libraries, frameworks, command-line tools, or packages without a service boundary

When NOT to Use

  • Smart contracts or blockchain modules with chain-specific semantics
  • Kernel or eBPF code
  • General Go style review without a security objective

Rationalizations to Reject

  • "Go is memory safe, so the code is safe." Most serious Go service bugs are trust-boundary and concurrency failures.
  • "The middleware handles auth." Verify every route, interceptor, and alternate entry path.
  • "The standard library prevents injection." It helps only when callers preserve its invariants.
  • "This only affects internal services." Internal service credentials and metadata endpoints are still security boundaries.
  • "The context will time out eventually." Missing cancellation and goroutine leaks become denial-of-service issues at scale.

Required Inputs

Collect these once if they are not explicit. Do not ask for a worker model by default; inherit the current session/client model. Honor a model only when the user explicitly names one that the client makes available.

ParameterValues
threat_modelREMOTE, LOCAL_UNPRIVILEGED, BOTH
severity_filterall, medium, high
scope_subpathoptional; defaults to .

Orchestration Workflow

Phase 1: Resolve Plugin Root

Resolve the directory containing prompts/clusters/manifest.json and go_inventory.go from ${CODEX_PLUGIN_ROOT}, ${CLAUDE_PLUGIN_ROOT}, or the installed location of this skill. Do not scan a user's home directory. Abort with an actionable error if no root resolves.

Require Go 1.22 or newer. The inventory is implemented with the Go standard library, uses the locally installed toolchain without automatic downloads, and does not fetch the target's module dependencies. Source using syntax newer than the installed Go version can still fail to parse.

Phase 2: Build Go Inventory

Choose output_dir as .go-review-results/<UTC timestamp>/, or use an external location requested by the user. Create it and run the inventory portably with:

sh
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/prepare_review.py" \
  --repo-root "." \
  --scope-subpath "${scope_subpath}" \
  --output-dir "${output_dir}"

Abort only if the inventory reports zero .go files. If has_service=false, skip the service-boundary and request-input clusters and continue with any other detected package capabilities.

The inventory schema remains at version 1. Its implementation uses Go syntax trees for imports, declarations, calls, routes, goroutines, and channel types; do not replace these results with text searches over source files.

This is conservative syntax analysis, not type or SSA analysis. It inventories all matching non-test .go files regardless of build tags, crosses nested Go modules within scope, and reports the review root's module in the top-level module field. Capability heuristics can still over-select a cluster; workers must verify reachability and data flow from source evidence.

Phase 3: Write Context

Read go-inventory.json and write context.md with YAML frontmatter:

  • threat_model
  • severity_filter
  • scope_subpath
  • go_file_count
  • package_count
  • every capability flag from the inventory
  • output_dir

The body must summarize:

  • service entry points and frameworks
  • untrusted input sources
  • trust boundaries and auth assumptions
  • outbound dependencies, storage, filesystem, templates, and crypto surfaces
  • concurrency and cgo/unsafe surfaces
Phase 4: Build Deterministic Run Plan

Run:

sh
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/build_run_plan.py" \
  --plugin-root "${GO_REVIEW_PLUGIN_ROOT}" \
  --output-dir "${output_dir}" \
  --threat-model "${threat_model}" \
  --severity-filter "${severity_filter}" \
  --scope-subpath "${scope_subpath}" \
  --context-roots "." \
  --has-service "${has_service}" \
  --has-outbound-http "${has_outbound_http}" \
  --has-sql "${has_sql}" \
  --has-exec "${has_exec}" \
  --has-fs-archive "${has_fs_archive}" \
  --has-template "${has_template}" \
  --has-crypto-auth "${has_crypto_auth}" \
  --has-concurrency "${has_concurrency}" \
  --has-unsafe-cgo "${has_unsafe_cgo}"

Read plan.json; do not manually re-derive cluster selection.

Show full SKILL.md (375 more words)Show less
Phase 5: Run Worker Protocols

The portable contracts are the bundled protocol files agents/go-review-worker.md, agents/go-review-dedup-judge.md, and agents/go-review-fp-judge.md. Do not assume those filenames are registered as callable agent names. Read the relevant protocol and pass it with each rendered prompt to the client-provided delegation mechanism. If delegation is not available, execute each assignment sequentially in the main session while preserving the same artifact contract.

Execution rules:

  • optional foreground cache primer
  • workers spawned foreground in waves of at most 16
  • no run_in_background=true
  • pass each rendered worker prompt verbatim
  • each worker writes findings, shard, and coverage artifacts
  • inherit the current session/client model unless the user explicitly selected an available model

If plan.json contains zero workers, create an empty findings-index.txt, note that no capability-gated clusters were selected in run-summary.md, and proceed to reporting. Do not treat an ordinary package with no selected clusters as a workflow failure.

Phase 6: Validate Worker Artifacts

For each completed worker, run:

sh
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/validate_artifacts.py" \
  "${output_dir}/plan.json" \
  --worker "worker-N" \
  --claimed-count "worker-N=<count>"

After all workers complete, reconcile shards and initialize deterministic empty reports when applicable:

sh
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/finalize_run.py" "${output_dir}"

This builds findings-index.txt from the union of worker shards and findings/*.md, retains orphan findings, and records incomplete shards in run-summary.md; do not silently drop a finding because a worker crashed after writing it.

Phase 7: Judges and Reports

Run the bundled dedup protocol, then the bundled FP protocol, each with output_dir in the prompt. The FP judge also receives the absolute path to generate_sarif.py. Use delegated workers when available or execute these protocols sequentially in the main session.

Always run the SARIF safety net:

sh
python3 "${GO_REVIEW_PLUGIN_ROOT}/scripts/generate_sarif.py" "${output_dir}"

Return REPORT.md, REPORT.sarif, go-inventory.json, and run-summary.md.

Success Criteria

  • go-inventory.json exists and reports at least one Go file
  • every planned worker has a coverage file and shard
  • findings-index.txt exists even for zero findings
  • dedup-summary.md, fp-summary.md, REPORT.md, and REPORT.sarif exist
  • any truncated or failed worker is surfaced in run-summary.md

Artifact Sensitivity

.go-review-results/ may contain source excerpts, suspected vulnerabilities, and absolute local paths. Treat it as sensitive assessment data. Before sharing or committing it, review and redact the contents. Recommend that users ignore the directory in the target repository or choose an external output location, but do not modify .gitignore without permission.

Source Provenance

The implementation approach and security-review taxonomy are annotated in references/provenance.md. Treat those sources as guidance; findings still require evidence from the repository under review.

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/go-review/skills/go-review of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit e655f93

Compare with similar skills

Go Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Go Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Go Review this skillSpecterOps/skills706—~2.1kAutomated safety check: PassApache-2.0
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Security Reviewliuyanghejerry/Clausura204—~106Automated safety check: PassMIT
Static Vulnerability DetectorArabelaTso/Skills-4-SE253—~2kAutomated safety check: PassApache-2.0
File To Codejeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
API Security ReviewOWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.0

Similar skills

  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Security Review

    liuyanghejerry/Clausura

    检查 SQL 注入、XSS、硬编码密钥

    204 GitHub stars~106 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Static Vulnerability Detector

    ArabelaTso/Skills-4-SE

    Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…

    253 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • File To Code

    jeremylongshore/tons-of-skills-marketplace

    Generates production-ready code from file specifications such as CSV files, JSON schemas, SQL DDL, protobuf definitions, or requirements documents.

    2.8k GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    188 GitHub stars~744 tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Offensive API Security

    SnailSploit/Claude-Red

    Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.

    7.4k GitHub stars~5k tokensUpdated 20 days ago
    SecurityAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    706 GitHub stars~805 tokensUpdated 16 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    706 GitHub stars~1.5k tokensUpdated 16 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    706 GitHub stars~2.4k tokensUpdated 16 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    706 GitHub stars~665 tokensUpdated 16 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    706 GitHub stars~738 tokensUpdated 16 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    706 GitHub stars~813 tokensUpdated 16 days ago
    Auto-check passed

Works with

Questions about Go Review

What does Go Review do?

Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications. Go Review is an agent skill from SpecterOps/skills. Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.

When should I use Go Review?

Go Review fits situations like: tasks that involve Security review; tasks that involve gRPC and Protobuf; tasks that involve Web application vulnerabilities.

How do I install Go Review in Claude Code?

Run `npx skills add SpecterOps/skills --skill go-review -a claude-code`. Or copy the skill folder (plugins/go-review/skills/go-review in SpecterOps/skills) into .claude/skills/go-review in your project. Claude Code loads it when a task matches its description.

How do I install Go Review in Codex?

Run `npx skills add SpecterOps/skills --skill go-review -a codex`. Or copy the skill folder (plugins/go-review/skills/go-review in SpecterOps/skills) into .agents/skills/go-review in your project. Codex loads it when a task matches its description.

Can I use Go Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill go-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/go-review, .gemini/skills/go-review, .github/skills/go-review and .opencode/skills/go-review in your project.

What does Go Review need to run?

Going by SKILL.md and its folder, Go Review needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Go Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Go Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Go Review use?

Go Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Go Review use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Go Review?

Skills that share tags, products or a category with Go Review: Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Security Review (liuyanghejerry/Clausura, 204 stars), Static Vulnerability Detector (ArabelaTso/Skills-4-SE, 253 stars) and File To Code (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Go Review?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 706 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.