golang-securitySecurity best practices and vulnerability prevention for Golang. Covers injection (SQL, command, XSS), cryptography, filesystem safety, network security, cookies, secrets management, memory safety, and logging. Apply when writing, reviewing, or auditing Go code for security, or when working on any risky code involving crypto, I/O, secrets management, user input handling, or authentication. Includes configuration of security tools.
Install via ClawdBot CLI:
clawdbot install samber/golang-securityGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdHardcoded API key or token pattern found in skill definition
AKIAIOSFODNN...Contains telemetry, tracking, or analytics calls not mentioned in documentation
analytics.Track(Potentially destructive shell commands in tool definitions
Exec(Generated Oct 6, 2026
A platform team uses the skill in Review mode to scan a pull request touching authentication middleware and SQL query builders. The agent traces call sites and data flows beyond the diff, surfacing a string-concatenated query that is only partially mitigated upstream, and adjusts severity rather than dismissing it.
A compliance-driven engineering org runs Audit mode to fan out five parallel sub-agents across injection, crypto/secrets, web headers, authz, and concurrency/dependency domains. Findings are aggregated, DREAD-scored, and each remediation is applied in its own worktree to produce isolated, revertible PRs ahead of the auditor's code review.
Backend engineers writing new handlers in Coding mode ask the skill to enforce parameterized queries, escape HTML output, and validate path inputs. A background agent greps newly written code for common vulnerability patterns while the primary agent implements the feature, catching an unsafe exec.Command invocation before commit.
A DevOps team receives a critical vulnerability report from govulncheck in a production Go binary. The skill guides triage, confirms whether the vulnerable symbol is actually reachable, and applies the dependency upgrade along with regression tests in an isolated worktree for a focused PR.
Engineering leadership points new hires to the skill's three-question trust-boundary model and review guidance, using it as an interactive mentor that explains why a file-path traversal is dangerous and how to fix it. This replaces a static wiki page with on-demand, context-aware coaching inside their editor.
Sell seats to application security and platform engineering teams who embed the skill into CI/CD and local agent workflows. The skill becomes a force multiplier for scarce security reviewers by automating first-pass audits and producing auditable findings with DREAD scores.
Offer the MIT-licensed core skill for free while monetizing enterprise features such as centralized finding dashboards, SOC 2 / ISO 27001 evidence exports, and policy-as-code enforcement across many repos.
Bundle the skill with human security engineers who validate AI-generated findings and sign off on remediation PRs for customers without in-house AppSec. The skill handles the first pass while experts focus on complex, high-severity issues.
💬 Integration Tip
Install govulncheck via `go install golang.org/x/vuln/cmd/govulncheck@latest` and invoke the skill explicitly in Review, Audit, or Coding mode depending on whether you are scanning a PR, an entire codebase, or new code; on Claude Code, pair it with `ultrathink` and `ultracode` for deeper reasoning and parallel sub-agent coverage.
Scored Sep 2, 2026
Calls external URL not in known-safe list
https://github.com/samber/cc-skills-golangAI Analysis
The skill definition shows no evidence of data exfiltration, credential harvesting, or hidden malicious instructions. The flagged signals are false positives: the credential pattern is a placeholder example, the file path is a common security reference, and the external URL is the skill's documented homepage. The skill's purpose and toolset are consistent with security auditing.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...