Installs into .claude/skills of the current project.
Are you the author of Go Security?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/dankosik-go-security)
---
name: go-security
description: "Use when identity, authorization, tenancy, tokens, secrets, injection, SSRF, abuse, or another trust boundary changes what an attacker can reach."
metadata:
invocation: model
kind: method
---
# Go Security
Security work walks **attacker paths** from trust boundary through principal,
authority, asset, enforcement point, attacker action, and observable denial.
`boundary -> principal -> enforcement -> action -> failure -> negative proof`
For a delegated Decision or Review, or when the active artifact requires its
result interface, load the
[shared specialist contract](../../contracts/specialist-contract.md).
When meaningful ordering, comparison, exhaustive accounting, or a required
decision/review handoff needs structured representation, trace each caller-controlled entrypoint to an asset or observable denial in
`AttackerPath{boundary, principal, asset, enforcement, action, failure,
denial_proof}` across route exposure, verified identity, objects reached,
outbound destinations, secrets, and caller-controlled work. Missing identity,
ambiguous tenant, or absent policy denies. Every accepted control needs focused
negative proof because an allow test also passes against a bypass.
Otherwise, a single local attacker path may retain its grounded judgment and
negative proof for its denial outcome.
Decide against existing owners: `internal/infra/oidcjwt` verifies tokens,
`api/openapi/service.yaml` declares default auth, `internal/infra/httpclient`
pins destinations, and `internal/config` separates secret inputs. Load the
[reference selector](references/index.md) for identity, exposure, interpreter
input, outbound destination, work amplification, or a secret sink.
For a **Decision**, disposition every reachable path with fail-closed behavior
and negative proof. For **Review**, follow each path into the shared finding
envelope; no findings still requires the focused deny proof. Load [access
control](../../../docs/universal-disciplines/auth-access-control/SKILL.md) when
the credential, permission, or revocation mechanism itself is open.