Skip to content
Back to skills

Eng Code Guidelines

ASecurity

Go production discipline for Compozy. Use when writing or editing non-test Go files under cmd or internal, including config, logging, CLI, concurrency, and process-lifecycle paths. Do not use for Go tests; pair it with the narrower schema, contract, or cleanup skill when those domains apply.

  • 2,785 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 3, 2026
testinggo

Works with

  • cli

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 30, 2026

npx -y skills add compozy/compozy --skill eng-code-guidelines --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Eng Code Guidelines?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Eng Code Guidelines
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/compozy-eng-code-guidelines/badge)](https://www.skillsdirectory.com/skills/compozy-eng-code-guidelines)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: eng-code-guidelines
description: >-
  Go production discipline for Compozy. Use when writing or editing non-test Go
  files under cmd or internal, including config, logging, CLI, concurrency, and
  process-lifecycle paths. Do not use for Go tests; pair it with the narrower
  schema, contract, or cleanup skill when those domains apply.
trigger: implicit
---

# Compozy Code Guidelines

Apply repository-specific Go conventions to production files under `cmd/` and `internal/`. Read the relevant sections of `references/coding-style.md`; for goroutines, shared state, detached execution, subprocesses, shutdown, timers, locks, or channels, also use `references/concurrency-patterns.md`.

- Trace the changed behavior through its applicable error, context, configuration, CLI, logging, type, and resource boundaries. Fix touched violations without expanding into unrelated debt.
- Each changed resource, goroutine, process, or mutable shared state has an owner. Use `eng-cleanup-failure-paths` when multiple fallible acquisitions make partial failure relevant.
- Add a companion skill only for a distinct unresolved concern. `golang-master` supplies deeper language guidance when needed; it is not an automatic prerequisite.
- For public behavior/contract changes, update the owning `docs/_memory/change-impact.md` audit. Cite an existing spec/task/PR audit instead of writing one per skill.

Run the focused owning check and reuse current scoped lint/race evidence. Cross-build and Linux-race parity checks follow the concurrency reference's applicable branches. Root `make gate` and PR CI policy apply at the enclosing commit/push or PR-delivery stage, not after each edit.

## Specific failure cases

- A dependency with only string errors may need one typed wrapper at its boundary so downstream code can match error identity.
- Reflection in codegen/decoders needs an adjacent reason; lint exceptions retain a justified `//nolint:` directive.
- A reachable production panic needs an explicit error path. For a proven unreachable invariant, prefer `panic("invariant: ...")` with its explanation over `log.Fatal`.
- For silently ignored CLI flags, check `cmd.Flags().Changed(name)`, the documented resolution chain, and the default-resolution debug log.

Files in this skill

  • SKILL.md3.8 KB
  • references/coding-style.md4.1 KB
  • references/concurrency-patterns.md2.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…