Security Scan
ericrisco/rsc-harness
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…
$ npx skills add unxed/f4 --skill golang-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install unxed/f4 golang-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/golang-security .claude/skills/golang-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "golang-security" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/golang-security into .claude/skills/golang-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/unxed/f4/tree/main/.agents/skills/golang-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add unxed/f4 --skill golang-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install unxed/f4 golang-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/golang-security .agents/skills/golang-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "golang-security" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/golang-security into .agents/skills/golang-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add unxed/f4 --skill golang-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install unxed/f4 golang-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/golang-security .cursor/skills/golang-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "golang-security" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/golang-security into .cursor/skills/golang-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/unxed/f4.git --path .agents/skills/golang-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add unxed/f4 --skill golang-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install unxed/f4 golang-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/golang-security .gemini/skills/golang-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "golang-security" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/golang-security into .gemini/skills/golang-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install unxed/f4 golang-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add unxed/f4 --skill golang-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/golang-security .github/skills/golang-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "golang-security" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/golang-security into .github/skills/golang-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add unxed/f4 --skill golang-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install unxed/f4 golang-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/unxed/f4.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/golang-security .opencode/skills/golang-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "golang-security" agent skill from https://github.com/unxed/f4/tree/main/.agents/skills/golang-security into .opencode/skills/golang-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "golang-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
golang-securitySecurity best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…
Golang Security is an agent skill from unxed/f4. Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus gosec SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice…
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including reference files (for example `evals/evals.json`, `references/architecture.md` and `references/checklist.md`). Compatibility notes: Designed for Claude Code, Codex or similar harness, and for projects using Golang.
It sits in Security, covering Threat modeling, Web application vulnerabilities and Vulnerability scanning. It works with Go and SQL. The repository describes itself as: dual pane like a charm. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 772edc7. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadEditWriteGlobGrepBash(go:*)Bash(golangci-lint:*)Bash(git:*)AgentWebFetch…and 5 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
go.devgithub.compkg.go.devowasp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code, Codex or similar harness, and for projects using Golang.
From compatibility in the SKILL.md frontmatter.
Golang Security loads about 3.6k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 209 tokens; SKILL.md has 1,428 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from unxed/f4 at commit 772edc7, republished under its MIT licence (© unxed). 1,428 words, ~3,560 tokens.
.claude/skills/golang-security/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.Persona: You are a senior Go security engineer. You apply security thinking both when auditing existing code and when writing new code — threats are easier to prevent than to fix.
Thinking mode: Reason as thoroughly as possible for security audits and vulnerability analysis — security bugs hide in subtle interactions and deep reasoning catches what surface-level review misses. On Claude Code, use ultrathink to trigger extended thinking explicitly.
Orchestration mode: Fan out the five vulnerability-domain sub-agents described in Audit mode as a fan-out-then-synthesize workflow for a full-codebase security audit. Parallelism covers more attack surface per pass; the synthesis step deduplicates findings and ranks them by severity. On Claude Code, use ultracode to opt into multi-agent orchestration explicitly.
Modes:
Dependencies:
go install golang.org/x/vuln/cmd/govulncheck@latestSecurity in Go follows the principle of defense in depth: protect at multiple layers, validate all inputs, use secure defaults, and leverage the standard library's security-aware design. Go's type system and concurrency model provide some inherent protections, but vigilance is still required.
Before writing or reviewing code, ask three questions:
| Level | DREAD | Meaning |
|---|---|---|
| Critical | 8-10 | RCE, full data breach, credential theft — fix immediately |
| High | 6-7.9 | Auth bypass, significant data exposure, broken crypto — fix in current sprint |
| Medium | 4-5.9 | Limited exposure, session issues, defense weakening — fix in next sprint |
| Low | 1-3.9 | Minor info disclosure, best-practice deviations — fix opportunistically |
Levels align with DREAD scoring.
Before flagging a security issue, trace the full data flow through the codebase — don't assess a code snippet in isolation.
Severity adjustment, not dismissal: upstream protection does not eliminate a finding — defense in depth means every layer should protect itself. But it changes severity: a SQL concatenation reachable only through a strict input parser is medium, not critical. Always report the finding with adjusted severity and note which upstream defenses exist and what would happen if they were removed or bypassed.
When downgrading or skipping a finding: add a brief inline comment (e.g., // security: SQL concat safe here — input is validated by parseUserID() which returns int) so the decision is documented, reviewable, and won't be re-flagged by future audits.
Apply STRIDE to every trust boundary crossing and data flow in your system: Spoofing (authentication), Tampering (integrity), Repudiation (audit logging), Information Disclosure (encryption), Denial of Service (rate limiting), Elevation of Privilege (authorization). Score each threat using DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability) to prioritize remediation — Critical (8-10) demands immediate action.
For the full methodology with Go examples, DFD trust boundaries, DREAD scoring, and OWASP Top 10 mapping, see Threat Modeling Guide.
| Severity | Vulnerability | Defense | Standard Library Solution |
|---|---|---|---|
| Critical | SQL Injection | Parameterized queries separate data from code | database/sql with ? placeholders |
| Critical | Command Injection | Pass args separately, never via shell concatenation | exec.Command with separate args |
| High | XSS | Auto-escaping renders user data as text, not HTML/JS | html/template, text/template |
| High | Path Traversal | Scope untrusted file access to an allowed root | Go 1.24+: use os.Root. Pre-Go 1.24: use filepath.IsLocal + filepath.Rel + separator-aware checks; never rely on filepath.Clean + strings.HasPrefix alone. |
| Medium | Timing Attacks | Constant-time comparison avoids byte-by-byte leaks | crypto/subtle.ConstantTimeCompare |
| High | Crypto Issues | Use vetted algorithms; never roll your own | crypto/aes, crypto/rand |
| Medium | HTTP Security | TLS + security headers prevent downgrade attacks | net/http, configure TLSConfig |
| Low | Missing Headers | HSTS, CSP, X-Frame-Options prevent browser attacks | Security headers middleware |
| Medium | Rate Limiting | Rate limits prevent brute-force and resource exhaustion | golang.org/x/time/rate, server timeouts |
| High | Race Conditions | Protect shared state to prevent data corruption | sync.Mutex, channels, avoid shared state |
For complete examples, code snippets, and CWE mappings, see:
unsafe usage.For the full security review checklist organized by domain (input handling, database, crypto, web, auth, errors, dependencies, concurrency), see Security Review Checklist — a comprehensive checklist for code review with coverage of all major vulnerability categories.
Security-relevant linters: bodyclose, sqlclosecheck, nilerr, errcheck, govet, staticcheck. See the samber/cc-skills-golang@golang-lint skill for configuration and usage.
For deeper security-specific analysis:
# Go security checker (SAST)
go get -tool github.com/securego/gosec/v2/cmd/gosec@latest
go tool gosec ./...
# Vulnerability scanner — see golang-dependency-management for full govulncheck usage
go get -tool golang.org/x/vuln/cmd/govulncheck@latest
go tool govulncheck ./...To check the known CVEs of a specific module or version without scanning the whole tree (e.g. when vetting a dependency on pkg.go.dev), → See samber/cc-skills-golang@golang-pkg-go-dev skill.
# Race detector
go test -race ./...
# Fuzz testing
go test -fuzz=Fuzz| Severity | Mistake | Fix |
|---|---|---|
| High | math/rand for tokens | Output is predictable — attacker can reproduce the sequence. Use crypto/rand |
| Critical | SQL string concatenation | Attacker can modify query logic. Parameterized queries keep data and code separate |
| Critical | exec.Command("bash -c") | Shell interprets metacharacters (;, |, `). Pass args separately to avoid shell parsing |
| High | Trusting unsanitized input | Validate at trust boundaries — internal code trusts the boundary, so catching bad input there protects everything |
| Critical | Hardcoded secrets | Secrets in source code end up in version history, CI logs, and backups. Use env vars or secret managers |
| Medium | Comparing secrets with == | == short-circuits on first differing byte, leaking timing info. Use crypto/subtle.ConstantTimeCompare |
| Medium | Returning detailed errors | Stack traces and DB errors help attackers map your system. Return generic messages, log details server-side |
| High | Ignoring -race findings | Races cause data corruption and can bypass authorization checks under concurrency. Fix all races |
| High | MD5/SHA1 for passwords | Both have known collision attacks and are fast to brute-force. Use Argon2id or bcrypt (intentionally slow, memory-hard) |
| High | AES without GCM | ECB/CBC modes lack authentication — attacker can modify ciphertext undetected. GCM provides encrypt+authenticate |
| Medium | Binding to 0.0.0.0 | Exposes service to all network interfaces. Bind to specific interface to limit attack surface |
| Severity | Anti-Pattern | Why It Fails | Fix |
|---|---|---|---|
| High | Security through obscurity | Hidden URLs are discoverable via fuzzing, logs, or source | Authentication + authorization on all endpoints |
| High | Trusting client headers | X-Forwarded-For, X-Is-Admin are trivially forged | Server-side identity verification |
| High | Client-side authorization | JavaScript checks are bypassed by any HTTP client | Server-side permission checks on every handler |
| High | Shared secrets across envs | Staging breach compromises production | Per-environment secrets via secret manager |
| Critical | Ignoring crypto errors | _, _ = encrypt(data) silently proceeds unencrypted | Always check errors — fail closed, never open |
| Critical | Rolling your own crypto | Custom encryption hasn't been analyzed by cryptographers | Use crypto/aes GCM, golang.org/x/crypto/argon2 |
See Security Architecture for detailed anti-patterns with Go code examples.
See samber/cc-skills-golang@golang-database, samber/cc-skills-golang@golang-safety, samber/cc-skills-golang@golang-observability, samber/cc-skills-golang@golang-continuous-integration skills.
samber/cc-skills-golang@golang-continuous-integration skill for automated AI-driven code review in CI using these guidelines© unxed, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (references) in .agents/skills/golang-security of unxed/f4.
Open the folder on GitHubat commit 772edc7
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in unxed/f4, which our catalogue first saw on October 7, 2026.
Golang Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Golang Security this skillunxed/f4 | 243 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Security Scanericrisco/rsc-harness | 180 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 425 | — | ~2.7k | Automated safety check: Pass | None | |
| Security Auditstaruhub/ClaudeSkills | 728 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Sast BanditAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~2.6k | Automated safety check: Pass | Custom licence | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT |
ericrisco/rsc-harness
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
staruhub/ClaudeSkills
全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…
AgentSecOps/SecOpsAgentKit
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
mukul975/Anthropic-Cybersecurity-Skills
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.
unxed/f4
Comprehensive documentation guide for Golang projects, covering godoc comments, README, CONTRIBUTING, CHANGELOG, Go Playground, Example tests, API docs, and llms.txt.
unxed/f4
Golang code style conventions — line length and breaking, variable declarations, control flow clarity, when comments help vs hurt.
unxed/f4
Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…
unxed/f4
Security audit checklist based on OWASP Top 10 and best practices.
unxed/f4
Go (Golang) naming conventions — covers packages, constructors, structs, interfaces, constants, enums, errors, booleans, receivers, getters/setters, functional options, acronyms, test functions, and…
unxed/f4
Golang concurrency design — goroutine lifecycle and leak prevention, channels and select, channel ownership and direction, sync.Mutex/RWMutex/sync.Map/sync.Once/atomics, errgroup, singleflight…
Categories
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…. Golang Security is an agent skill from unxed/f4. Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus gosec SAST, race detection, and fuzz testing.
Golang Security fits situations like: tasks that involve Threat modeling; tasks that involve Web application vulnerabilities; tasks that involve Vulnerability scanning.
Run `npx skills add unxed/f4 --skill golang-security -a claude-code`. Or copy the skill folder (.agents/skills/golang-security in unxed/f4) into .claude/skills/golang-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add unxed/f4 --skill golang-security -a codex`. Or copy the skill folder (.agents/skills/golang-security in unxed/f4) into .agents/skills/golang-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add unxed/f4 --skill golang-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/golang-security, .gemini/skills/golang-security, .github/skills/golang-security and .opencode/skills/golang-security in your project.
Going by SKILL.md and its folder, Golang Security needs the command-line tools its instructions call (go). Its frontmatter pre-approves these tools: Read, Edit, Write, Glob, Grep, Bash(go:*), Bash(golangci-lint:*), Bash(git:*), Agent, WebFetch, Bash(govulncheck:*), WebSearch, AskUserQuestion, EnterWorktree, ExitWorktree. Compatibility (from SKILL.md): Designed for Claude Code, Codex or similar harness, and for projects using Golang..
SKILL.md names 4 domains. As links in the text: go.dev, github.com, pkg.go.dev and owasp.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Golang Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Golang Security: Security Scan (ericrisco/rsc-harness, 180 stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars), Security Audit (staruhub/ClaudeSkills, 728 stars) and Sast Bandit (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
unxed (a GitHub user) maintains it in unxed/f4, which has 243 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 10, 2026.
Source: unxed/f4 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.