Golang security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/golang-security
Security standards for Go backend services. Use when implementing input validation, crypto, or SQL injection prevention in Go. (triggers: crypto/rand, argon2, sanitize, jwt, bcrypt, validation, input validation, sql injection)From its SKILL.md
npx -y skills add ComeOnOliver/skillshub --skill golang-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
2.0 KB, 444 tokens by cl100k_base, as published. Nobody here has run it
Golang Security Standards
Priority: P0 (CRITICAL)
Implementation Guidelines
Input Validation
- Validation: Use
go-playground/validatororgoogle/go-cmpfor struct validation. - Sanitization: Sanitize user input before processing. Use
bluemondayfor HTML sanitization.
Cryptography
- Random: ALWAYS use
crypto/rand, NEVERmath/randfor security-sensitive operations (tokens, keys, IVs). - Hashing: Use Argon2id for password hashing (
golang.org/x/crypto/argon2). Do NOT use bcrypt (weaker) or MD5/SHA1 (insecure). Recommended params:time=1, memory=64MB, threads=4. - Encryption: Use
crypto/aeswith GCM mode for authenticated encryption.
SQL Injection Prevention
- Parameterized Queries: ALWAYS use
$1, $2placeholders withdatabase/sqlor ORM (GORM, sqlx). - No String Concatenation: Never build queries with
fmt.Sprintf().
Authentication
- JWT: Use
golang-jwt/jwtv5+. EnforceRS256(preferred) orHS256. Rejectnoneand symmetric algorithms for multi-service auth. Validatealg,iss,aud,expclaims. - Sessions: Use secure, httpOnly cookies with
gorilla/sessions.
Secret Management
- Environment Variables: Load secrets via
godotenvor Kubernetes secrets. - No Hardcoding: Never commit API keys, passwords, or tokens to Git.
Anti-Patterns
- No
math/randfor Security: RNG is predictable. Usecrypto/rand. - No
fmt.Sprintf()for SQL: Causes SQL injection. Use placeholders. - No bcrypt or MD5 for Passwords: Use
argon2idexclusively. - No Exposed Error Details: Don't leak stack traces to clients in production.
References
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.