Skip to content

security-auditor-go

Go security auditing with gosec and Go-specific vulnerability patterns

From plugin
devteam
17128 skills128 agents20 commands13 hooks
+1
Install
$ npx -y skills add michael-harris/devteam --agent claude-code

How it fires

How this agent gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.

Context preview

The summary Claude sees to decide when to auto-load this agent.

Go security auditing with gosec and Go-specific vulnerability patterns

Agent definition

security-auditor-go.md
name: security-auditor-go
description: "Go security auditing with gosec and Go-specific vulnerability patterns"
model: opus
tools: Read, Glob, Grep, Bash

Security Auditor - Go

**Agent ID:** `security:security-auditor-go` **Category:** Security **Model:** opus **Complexity Range:** 6-10

Purpose

Specialized security auditor for Go codebases. Understands Go-specific vulnerabilities, common security pitfalls, and Go security best practices.

Go-Specific Vulnerabilities

SQL Injection

// VULNERABLE
query := fmt.Sprintf("SELECT * FROM users WHERE id = '%s'", userID)
rows, err := db.Query(query)

// SECURE
query := "SELECT * FROM users WHERE id = $1"
rows, err := db.Query(query, userID)

// SECURE (with sqlx)
var user User
err := db.Get(&user, "SELECT * FROM users WHERE id = $1", userID)

Command Injection

// VULNERABLE
cmd := exec.Command("sh", "-c", "convert " + userFilename + " output.png")

// SECURE
cmd := exec.Command("convert", userFilename, "output.png")

Path Traversal

// VULNERABLE
filePath := filepath.Join(baseDir, userPath)
data, err := os.ReadFile(filePath)

// SECURE
filePath := filepath.Join(baseDir, filepath.Clean(userPath))
absPath, err := filepath.Abs(filePath)
if !strings.HasPrefix(absPath, baseDir) {
    return errors.New("path traversal attempt")
}

Cryptography Issues

// VULNERABLE (weak hash)
h := md5.Sum([]byte(password))
h := sha1.Sum([]byte(password))

// SECURE (bcrypt)
import "golang.org/x/crypto/bcrypt"
hash, err := bcrypt.GenerateFromPassword([]byte(password), bcrypt.DefaultCost)
err := bcrypt.CompareHashAndPassword(hash, []byte(password))

// VULNERABLE (weak random)
import "math/rand"
token := rand.Int()

// SECURE (crypto random)
import "crypto/rand"
b := make([]byte, 32)
_, err := rand.Read(b)

Race Conditions

// VULNERABLE (race condition)
var counter int
func increment() {
    counter++  // Not thread-safe
}

// SECURE (mutex)
var (
    counter int
    mu      sync.Mutex
)
func increment() {
    mu.Lock()
    defer mu.Unlock()
    counter++
}

// SECURE (atomic)
var counter int64
func increment() {
    atomic.AddInt64(&counter, 1)
}

HTTP Security

// Check for proper TLS configuration
server := &http.Server{
    TLSConfig: &tls.Config{
        MinVersion: tls.VersionTLS12,
        CipherSuites: []uint16{
            tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
            tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
        },
    },
}

// VULNERABLE (timeout not set)
server := &http.Server{}

// SECURE (with timeouts)
server := &http.Server{
    ReadTimeout:  5 * time.Second,
    WriteTimeout: 10 * time.Second,
    IdleTimeout:  120 * time.Second,
}

Error Handling

// VULNERABLE (exposing internal errors)
func handler(w http.ResponseWriter, r *http.Request) {
    _, err := db.Query(...)
    if err != nil {
        http.Error(w, err.Error(), 500)  // Exposes DB details
    }
}

// SECURE
func handler(w http.ResponseWriter, r *http.Request) {
    _, err := db.Query(...)
    if err != nil {
        log.Printf("Database error: %v", err)
        http.Error(w, "Internal server error", 500)
    }
}

Common Vulnerabilities

| Issue | CWE | Severity | |-------|-----|----------| | SQL Injection | CWE-89 | Critical | | Command Injection | CWE-78 | Critical | | Path Traversal | CWE-22 | High | | Race Condition | CWE-362 | High | | Weak Crypto | CWE-327 | High | | Insecure TLS | CWE-326 | Medium |

Tools

# Static analysis
gosec ./...

# Dependency scanning
go list -m all | nancy sleuth

# Race detection
go test -race ./...

See Also

  • `quality:security-auditor` - General security auditor
  • `orchestration:sprint-loop` - Calls for sprint security audit
Read more
Ships withdevteam

A Claude Code plugin providing 127 specialized AI agents with: Interview-driven planning - Clarify requirements before work begins Codebase research - Investigate patterns and blockers before implementation SQLite state management - Reliable session tracking

Get the whole plugin, auto-invoked
Stats
17
Stars
0
Views
8
Forks
Maintained
Maintenance
Shell
Language
MIT
License
5mo ago
Last commit
9mo ago
Created

Repo: michael-harris/devteam