Skip to content
Development
Skill

/golang-security

Secure Go backend services against common vulnerabilities. Use when implementing input validation, crypto, or SQL injection prevention in Go.

From plugin
agent-skills-standard
538200 skills1 MCP
Install
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill golang-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/golang-security

Context preview

The summary Claude sees to decide when to auto-load this skill.

Secure Go backend services against common vulnerabilities. Use when implementing input validation, crypto, or SQL injection prevention in Go.

SKILL.md

golang-security.SKILL.md
name: golang-security
description: Secure Go backend services against common vulnerabilities. Use when implementing input validation, crypto, or SQL injection prevention in Go.
metadata:
  triggers:
    files:
    - 'crypto/rand'
    keywords:
    - argon2
    - sanitize
    - jwt
    - bcrypt
    - validation
    - input validation
    - sql injection

Golang Security Standards

**Priority: P0 (CRITICAL)**

Implementation Guidelines

Input Validation

  • **Validation**: Use `go-playground/validator` or `google/go-cmp` for struct validation.
  • **Sanitization**: Sanitize user input before processing. Use `bluemonday` for HTML sanitization.

Cryptography

  • **Random**: ALWAYS use `crypto/rand`, NEVER `math/rand` for security-sensitive operations (tokens, keys, IVs).
  • **Hashing**: Use **Argon2id** for password hashing (`golang.org/x/crypto/argon2`). NOT use bcrypt (weaker) or MD5/SHA1 (insecure). Recommended params: `time=1, memory=64MB, threads=4`.
  • **Encryption**: Use `crypto/aes` with GCM mode for authenticated encryption.

SQL Injection Prevention

  • **Parameterized Queries**: ALWAYS use `$1, $2` placeholders with `database/sql` or ORM (GORM, sqlx).
  • **No String Concatenation**: Never build queries with `fmt.Sprintf()`.

Authentication

  • **JWT**: Use `golang-jwt/jwt` v5+. Enforce `RS256` (preferred) or `HS256`. **Reject `none` and symmetric algorithms for multi-service auth**. Validate `alg`, `iss`, `aud`, `exp` claims.
  • **Sessions**: Use secure, httpOnly cookies with `gorilla/sessions`.

Secret Management

  • **Environment Variables**: Load secrets via `godotenv` or Kubernetes secrets.
  • **No Hardcoding**: Never commit API keys, passwords, or tokens to Git.

Anti-Patterns

  • **No `math/rand` for Security**: RNG predictable. Use `crypto/rand`.
  • **No `fmt.Sprintf()` for SQL**: Causes SQL injection. Use placeholders.
  • **No bcrypt or MD5 for Passwords**: Use `argon2id` exclusively.
  • **No Exposed Error Details**: Don't leak stack traces to clients in production.

References

  • [Implementation Examples](references/implementation.md)
Read more
Ships withagent-skills-standard

The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.

Get the whole plugin

Other skills on agent-skills-standard.