Agent skill

Golang Security

by unxed in unxed/f4

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

MITAuto-check passedSecurity

Install Golang Security

skills CLI
$ npx skills add unxed/f4 --skill golang-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install unxed/f4 golang-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/golang-security .claude/skills/golang-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
golang-security
GitHub stars
243
Used in
2 other repos
Token cost
~3.6k tokens
SKILL.md length
1,428 words
Files
14 (incl. references)
Skills in repo
36
Repo updated
First seen
Licence
MIT

At a glance

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

  • Works in 3 steps: What are the trust boundaries? — Where… → What can an attacker control? — Which… → What is the blast radius? — If this…
  • Tasks that involve Threat modeling
  • SKILL.md covers Overview, Security Thinking Model, Severity Levels and Research Before Reporting, plus 9 more sections
  • Calls go

What it does

Golang Security is an agent skill from unxed/f4. Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus gosec SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `evals/evals.json`, `references/architecture.md` and `references/checklist.md`). Compatibility notes: Designed for Claude Code, Codex or similar harness, and for projects using Golang.

It sits in Security, covering Threat modeling, Web application vulnerabilities and Vulnerability scanning. It works with Go and SQL. The repository describes itself as: dual pane like a charm. The licence is MIT.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/golang-security”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code, Codex or similar harness, and for projects using Golang.
  • Pre-approved tools (allowed-tools): Read, Edit, Write, Glob, Grep, Bash(go:*), Bash(golangci-lint:*), Bash(git:*), Agent, WebFetch, Bash(govulncheck:*), WebSearch, AskUserQuestion, EnterWorktree, ExitWorktree

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. What are the trust boundaries? — Where does untrusted data enter the system? (HTTP requests, file uploads, environment variables, database…
  2. What can an attacker control? — Which inputs flow into sensitive operations? (SQL queries, shell commands, HTML output, file paths…
  3. What is the blast radius? — If this defense fails, what's the worst outcome? (Data leak, RCE, privilege escalation, denial of service)

What it can do on your machine

Read from SKILL.md and the folder at commit 772edc7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Write
    • Glob
    • Grep
    • Bash(go:*)
    • Bash(golangci-lint:*)
    • Bash(git:*)
    • Agent
    • WebFetch

    …and 5 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • go.dev
    • github.com
    • pkg.go.dev
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code, Codex or similar harness, and for projects using Golang.

    From compatibility in the SKILL.md frontmatter.

Context cost

Golang Security loads about 3.6k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 209 tokens; SKILL.md has 1,428 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~209
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from unxed/f4 at commit 772edc7, republished under its MIT licence (© unxed). 1,428 words, ~3,560 tokens.

Download SKILL.mdSave it as .claude/skills/golang-security/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
golang-security
description
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus `gosec` SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice aliasing (→ See `samber/cc-skills-golang@golang-safety` skill), dependency vulnerability scanning with govulncheck (→ See `samber/cc-skills-golang@golang-dependency-management` skill), or wiring security scanners into CI pipelines (→ See `samber/cc-skills-golang@golang-continuous-integration` skill).
allowed-tools
Read, Edit, Write, Glob, Grep, Bash(go:*), Bash(golangci-lint:*), Bash(git:*), Agent, WebFetch, Bash(govulncheck:*), WebSearch, AskUserQuestion, EnterWorktree, ExitWorktree
compatibility
Designed for Claude Code, Codex or similar harness, and for projects using Golang.
user-invocable
true
license
MIT
metadata.author
samber
metadata.version
1.2.2
paths
**/*.go

Persona: You are a senior Go security engineer. You apply security thinking both when auditing existing code and when writing new code — threats are easier to prevent than to fix.

Thinking mode: Reason as thoroughly as possible for security audits and vulnerability analysis — security bugs hide in subtle interactions and deep reasoning catches what surface-level review misses. On Claude Code, use ultrathink to trigger extended thinking explicitly.

Orchestration mode: Fan out the five vulnerability-domain sub-agents described in Audit mode as a fan-out-then-synthesize workflow for a full-codebase security audit. Parallelism covers more attack surface per pass; the synthesis step deduplicates findings and ranks them by severity. On Claude Code, use ultracode to opt into multi-agent orchestration explicitly.

Modes:

  • Review mode — reviewing a PR for security issues. Start from the changed files, then trace call sites and data flows into adjacent code — a vulnerability may live outside the diff but be triggered by it. Sequential.
  • Audit mode — full codebase security scan. Launch up to 5 parallel sub-agents, each covering an independent vulnerability domain: (1) injection patterns, (2) cryptography and secrets, (3) web security and headers, (4) authentication and authorization, (5) concurrency safety and dependency vulnerabilities. Aggregate findings, score with DREAD, and report by severity. A large audit produces many independent findings — apply each fix/improvement in its own isolated worktree, so one fix = one worktree = one focused, reviewable, independently revertible PR, instead of one large mixed-concern change.
  • Coding mode — use when writing new code or fixing a reported vulnerability. Follow the skill's sequential guidance. Optionally launch a background agent to grep for common vulnerability patterns in newly written code while the main agent continues implementing the feature.

Dependencies:

  • govulncheck: go install golang.org/x/vuln/cmd/govulncheck@latest

Go Security

Overview

Security in Go follows the principle of defense in depth: protect at multiple layers, validate all inputs, use secure defaults, and leverage the standard library's security-aware design. Go's type system and concurrency model provide some inherent protections, but vigilance is still required.

Security Thinking Model

Before writing or reviewing code, ask three questions:

  1. What are the trust boundaries? — Where does untrusted data enter the system? (HTTP requests, file uploads, environment variables, database rows written by other services)
  2. What can an attacker control? — Which inputs flow into sensitive operations? (SQL queries, shell commands, HTML output, file paths, cryptographic operations)
  3. What is the blast radius? — If this defense fails, what's the worst outcome? (Data leak, RCE, privilege escalation, denial of service)

Severity Levels

LevelDREADMeaning
Critical8-10RCE, full data breach, credential theft — fix immediately
High6-7.9Auth bypass, significant data exposure, broken crypto — fix in current sprint
Medium4-5.9Limited exposure, session issues, defense weakening — fix in next sprint
Low1-3.9Minor info disclosure, best-practice deviations — fix opportunistically

Levels align with DREAD scoring.

Research Before Reporting

Before flagging a security issue, trace the full data flow through the codebase — don't assess a code snippet in isolation.

  1. Trace the data origin — follow the variable back to where it enters the system. Is it user input, a hardcoded constant, or an internal-only value?
  2. Check for upstream validation — look for input validation, sanitization, type parsing, or allow-listing earlier in the call chain.
  3. Examine the trust boundary — if the data never crosses a trust boundary (e.g., internal service-to-service with mTLS), the risk profile is different.
  4. Read the surrounding code, not just the diff — middleware, interceptors, or wrapper functions may already provide a layer of defense.

Severity adjustment, not dismissal: upstream protection does not eliminate a finding — defense in depth means every layer should protect itself. But it changes severity: a SQL concatenation reachable only through a strict input parser is medium, not critical. Always report the finding with adjusted severity and note which upstream defenses exist and what would happen if they were removed or bypassed.

When downgrading or skipping a finding: add a brief inline comment (e.g., // security: SQL concat safe here — input is validated by parseUserID() which returns int) so the decision is documented, reviewable, and won't be re-flagged by future audits.

Threat Modeling (STRIDE)

Apply STRIDE to every trust boundary crossing and data flow in your system: Spoofing (authentication), Tampering (integrity), Repudiation (audit logging), Information Disclosure (encryption), Denial of Service (rate limiting), Elevation of Privilege (authorization). Score each threat using DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability) to prioritize remediation — Critical (8-10) demands immediate action.

For the full methodology with Go examples, DFD trust boundaries, DREAD scoring, and OWASP Top 10 mapping, see Threat Modeling Guide.

Quick Reference

SeverityVulnerabilityDefenseStandard Library Solution
CriticalSQL InjectionParameterized queries separate data from codedatabase/sql with ? placeholders
CriticalCommand InjectionPass args separately, never via shell concatenationexec.Command with separate args
HighXSSAuto-escaping renders user data as text, not HTML/JShtml/template, text/template
HighPath TraversalScope untrusted file access to an allowed rootGo 1.24+: use os.Root. Pre-Go 1.24: use filepath.IsLocal + filepath.Rel + separator-aware checks; never rely on filepath.Clean + strings.HasPrefix alone.
MediumTiming AttacksConstant-time comparison avoids byte-by-byte leakscrypto/subtle.ConstantTimeCompare
HighCrypto IssuesUse vetted algorithms; never roll your owncrypto/aes, crypto/rand
MediumHTTP SecurityTLS + security headers prevent downgrade attacksnet/http, configure TLSConfig
LowMissing HeadersHSTS, CSP, X-Frame-Options prevent browser attacksSecurity headers middleware
MediumRate LimitingRate limits prevent brute-force and resource exhaustiongolang.org/x/time/rate, server timeouts
HighRace ConditionsProtect shared state to prevent data corruptionsync.Mutex, channels, avoid shared state
Show full SKILL.md (537 more words)Show less

Detailed Categories

For complete examples, code snippets, and CWE mappings, see:

Code Review Checklist

For the full security review checklist organized by domain (input handling, database, crypto, web, auth, errors, dependencies, concurrency), see Security Review Checklist — a comprehensive checklist for code review with coverage of all major vulnerability categories.

Tooling & Verification

Static Analysis & Linting

Security-relevant linters: bodyclose, sqlclosecheck, nilerr, errcheck, govet, staticcheck. See the samber/cc-skills-golang@golang-lint skill for configuration and usage.

For deeper security-specific analysis:

bash
# Go security checker (SAST)
go get -tool github.com/securego/gosec/v2/cmd/gosec@latest
go tool gosec ./...

# Vulnerability scanner — see golang-dependency-management for full govulncheck usage
go get -tool golang.org/x/vuln/cmd/govulncheck@latest
go tool govulncheck ./...

To check the known CVEs of a specific module or version without scanning the whole tree (e.g. when vetting a dependency on pkg.go.dev), → See samber/cc-skills-golang@golang-pkg-go-dev skill.

Security Testing
bash
# Race detector
go test -race ./...

# Fuzz testing
go test -fuzz=Fuzz

Common Mistakes

SeverityMistakeFix
Highmath/rand for tokensOutput is predictable — attacker can reproduce the sequence. Use crypto/rand
CriticalSQL string concatenationAttacker can modify query logic. Parameterized queries keep data and code separate
Criticalexec.Command("bash -c")Shell interprets metacharacters (;, |, `). Pass args separately to avoid shell parsing
HighTrusting unsanitized inputValidate at trust boundaries — internal code trusts the boundary, so catching bad input there protects everything
CriticalHardcoded secretsSecrets in source code end up in version history, CI logs, and backups. Use env vars or secret managers
MediumComparing secrets with ==== short-circuits on first differing byte, leaking timing info. Use crypto/subtle.ConstantTimeCompare
MediumReturning detailed errorsStack traces and DB errors help attackers map your system. Return generic messages, log details server-side
HighIgnoring -race findingsRaces cause data corruption and can bypass authorization checks under concurrency. Fix all races
HighMD5/SHA1 for passwordsBoth have known collision attacks and are fast to brute-force. Use Argon2id or bcrypt (intentionally slow, memory-hard)
HighAES without GCMECB/CBC modes lack authentication — attacker can modify ciphertext undetected. GCM provides encrypt+authenticate
MediumBinding to 0.0.0.0Exposes service to all network interfaces. Bind to specific interface to limit attack surface

Security Anti-Patterns

SeverityAnti-PatternWhy It FailsFix
HighSecurity through obscurityHidden URLs are discoverable via fuzzing, logs, or sourceAuthentication + authorization on all endpoints
HighTrusting client headersX-Forwarded-For, X-Is-Admin are trivially forgedServer-side identity verification
HighClient-side authorizationJavaScript checks are bypassed by any HTTP clientServer-side permission checks on every handler
HighShared secrets across envsStaging breach compromises productionPer-environment secrets via secret manager
CriticalIgnoring crypto errors_, _ = encrypt(data) silently proceeds unencryptedAlways check errors — fail closed, never open
CriticalRolling your own cryptoCustom encryption hasn't been analyzed by cryptographersUse crypto/aes GCM, golang.org/x/crypto/argon2

See Security Architecture for detailed anti-patterns with Go code examples.

Cross-References

See samber/cc-skills-golang@golang-database, samber/cc-skills-golang@golang-safety, samber/cc-skills-golang@golang-observability, samber/cc-skills-golang@golang-continuous-integration skills.

  • → See samber/cc-skills-golang@golang-continuous-integration skill for automated AI-driven code review in CI using these guidelines

Additional Resources

© unxed, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references) in .agents/skills/golang-security of unxed/f4.

  • SKILL.md
  • evals/evals.json
  • references/architecture.md
  • references/checklist.md
  • references/cookies.md
  • references/cryptography.md
  • references/filesystem.md
  • references/injection.md
  • references/logging.md
  • references/memory-safety.md
  • references/network.md
  • references/secrets.md
  • references/third-party.md
  • references/threat-modeling.md

Open the folder on GitHubat commit 772edc7

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in unxed/f4, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Golang Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Golang Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Golang Security this skillunxed/f42432 repos~3.6kAutomated safety check: PassMIT
Security Scanericrisco/rsc-harness180—~2.8kAutomated safety check: NotesMIT
Secknowledge SkillPa55w0rd/secknowledge-skill425—~2.7kAutomated safety check: PassNone
Security Auditstaruhub/ClaudeSkills728—~1.3kAutomated safety check: NotesMIT
Sast BanditAgentSecOps/SecOpsAgentKit2201 repos~2.6kAutomated safety check: PassCustom licence
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    180 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    425 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Security Audit

    staruhub/ClaudeSkills

    全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

    728 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Sast Bandit

    AgentSecOps/SecOpsAgentKit

    Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

    220 GitHub starsUsed in 1 repo~2.6k tokens
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Implementing Devsecops Security Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from unxed/f4

All 36 skills in this repo
  • Comprehensive documentation guide for Golang projects, covering godoc comments, README, CONTRIBUTING, CHANGELOG, Go Playground, Example tests, API docs, and llms.txt.

    244 GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check passed
  • Golang code style conventions — line length and breaking, variable declarations, control flow clarity, when comments help vs hurt.

    244 GitHub starsUsed in 3 repos~2.5k tokens
    Auto-check passed
  • Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…

    244 GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check passed
  • Security audit checklist based on OWASP Top 10 and best practices.

    244 GitHub stars~5.4k tokensUpdated today
    Auto-check: notes
  • Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and…

    244 GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed
  • Golang concurrency design — goroutine lifecycle and leak prevention, channels and select, channel ownership and direction, sync.Mutex/RWMutex/sync.Map/sync.Once/atomics, errgroup, singleflight…

    244 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed

Works with

Categories

Questions about Golang Security

What does Golang Security do?

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…. Golang Security is an agent skill from unxed/f4. Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus gosec SAST, race detection, and fuzz testing.

When should I use Golang Security?

Golang Security fits situations like: tasks that involve Threat modeling; tasks that involve Web application vulnerabilities; tasks that involve Vulnerability scanning.

How do I install Golang Security in Claude Code?

Run `npx skills add unxed/f4 --skill golang-security -a claude-code`. Or copy the skill folder (.agents/skills/golang-security in unxed/f4) into .claude/skills/golang-security in your project. Claude Code loads it when a task matches its description.

How do I install Golang Security in Codex?

Run `npx skills add unxed/f4 --skill golang-security -a codex`. Or copy the skill folder (.agents/skills/golang-security in unxed/f4) into .agents/skills/golang-security in your project. Codex loads it when a task matches its description.

Can I use Golang Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unxed/f4 --skill golang-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/golang-security, .gemini/skills/golang-security, .github/skills/golang-security and .opencode/skills/golang-security in your project.

What does Golang Security need to run?

Going by SKILL.md and its folder, Golang Security needs the command-line tools its instructions call (go). Its frontmatter pre-approves these tools: Read, Edit, Write, Glob, Grep, Bash(go:*), Bash(golangci-lint:*), Bash(git:*), Agent, WebFetch, Bash(govulncheck:*), WebSearch, AskUserQuestion, EnterWorktree, ExitWorktree. Compatibility (from SKILL.md): Designed for Claude Code, Codex or similar harness, and for projects using Golang..

Does Golang Security access the network?

SKILL.md names 4 domains. As links in the text: go.dev, github.com, pkg.go.dev and owasp.org. This is read from the text; nothing was executed.

Is Golang Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Golang Security use?

Golang Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Golang Security use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to Golang Security?

Skills that share tags, products or a category with Golang Security: Security Scan (ericrisco/rsc-harness, 180 stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars), Security Audit (staruhub/ClaudeSkills, 728 stars) and Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Golang Security?

unxed (a GitHub user) maintains it in unxed/f4, which has 243 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 10, 2026.

Source: unxed/f4 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.