Skip to content
Back to skills

Go Security

ASecurity

Use when identity, authorization, tenancy, tokens, secrets, injection, SSRF, abuse, or another trust boundary changes what an attacker can reach.

  • 7 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
developmentrustgoapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add Dankosik/go-service-template-rest --skill go-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Go Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Go Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dankosik-go-security/badge)](https://www.skillsdirectory.com/skills/dankosik-go-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: go-security
description: "Use when identity, authorization, tenancy, tokens, secrets, injection, SSRF, abuse, or another trust boundary changes what an attacker can reach."
metadata:
  invocation: model
  kind: method
---

# Go Security

Security work walks **attacker paths** from trust boundary through principal,
authority, asset, enforcement point, attacker action, and observable denial.

`boundary -> principal -> enforcement -> action -> failure -> negative proof`

For a delegated Decision or Review, or when the active artifact requires its
result interface, load the
[shared specialist contract](../../contracts/specialist-contract.md).
When meaningful ordering, comparison, exhaustive accounting, or a required
decision/review handoff needs structured representation, trace each caller-controlled entrypoint to an asset or observable denial in
`AttackerPath{boundary, principal, asset, enforcement, action, failure,
denial_proof}` across route exposure, verified identity, objects reached,
outbound destinations, secrets, and caller-controlled work. Missing identity,
ambiguous tenant, or absent policy denies. Every accepted control needs focused
negative proof because an allow test also passes against a bypass.
Otherwise, a single local attacker path may retain its grounded judgment and
negative proof for its denial outcome.

Decide against existing owners: `internal/infra/oidcjwt` verifies tokens,
`api/openapi/service.yaml` declares default auth, `internal/infra/httpclient`
pins destinations, and `internal/config` separates secret inputs. Load the
[reference selector](references/index.md) for identity, exposure, interpreter
input, outbound destination, work amplification, or a secret sink.

For a **Decision**, disposition every reachable path with fail-closed behavior
and negative proof. For **Review**, follow each path into the shared finding
envelope; no findings still requires the focused deny proof. Load [access
control](../../../docs/universal-disciplines/auth-access-control/SKILL.md) when
the credential, permission, or revocation mechanism itself is open.

Files in this skill

  • SKILL.md2.1 KB
  • references/abuse-and-cost-bounds.md2.4 KB
  • references/contract-exposure.md2.8 KB
  • references/index.md1.9 KB
  • references/outbound-egress.md2.5 KB
  • references/secrets-and-disclosure.md2.4 KB
  • references/untrusted-input.md2.5 KB
  • references/verified-principal.md3.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…