golang-security
samber/cc-skills-golang
Security best practices and vulnerability prevention for Go: injection, cryptography, secrets, threat modeling, and SAST tooling.
What is golang-security?
A comprehensive security skill for Go development covering injection attacks (SQL, command, XSS), cryptographic best practices, secrets management, path traversal, SSRF, HTTP security, and threat modeling with STRIDE/DREAD. Use when writing, reviewing, or auditing Go code that handles user input, authentication, crypto, file/network I/O, or secrets.
- Identify and prevent injection vulnerabilities (SQL, command, XSS) with parameterized queries and proper escaping
- Apply cryptographic best practices using Go's standard library (crypto/aes, crypto/rand, crypto/subtle)
- Detect and fix path traversal, SSRF, and HTTP security header issues
- Manage secrets securely and prevent PII leakage in logs
- Perform threat modeling using STRIDE methodology and DREAD scoring
- Run gosec SAST analysis, race detection, and fuzz testing for vulnerability discovery
How to install golang-security
npx skills add https://github.com/samber/cc-skills-golang --skill golang-security- Go installed and configured
- govulncheck installed: `go install golang.org/x/vuln/cmd/govulncheck@latest`
How to use golang-security
- 1.Identify the trust boundaries and data flows in the code you're reviewing or writing
- 2.Ask: What untrusted data enters the system, and where does it flow to sensitive operations?
- 3.Trace user input through the codebase to check for validation, sanitization, and proper escaping
- 4.Apply the appropriate defense (parameterized queries for SQL, separate args for exec.Command, html/template for XSS, etc.)
- 5.Run gosec SAST and govulncheck to detect injection patterns and dependency vulnerabilities
- 6.Score findings using DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability) and prioritize by severity
- 7.Document security decisions inline with comments explaining why a pattern is safe or what upstream defenses exist
Use cases
- Reviewing a pull request for security vulnerabilities before merge
- Conducting a full codebase security audit across multiple vulnerability domains in parallel
- Writing new authentication or payment-processing code with security-first design
- Fixing a reported vulnerability with proper threat modeling and defense-in-depth approach
- Auditing third-party integrations that handle user data or secrets
- Go developers writing security-sensitive code (auth, crypto, user input handling)
- Security engineers auditing Go codebases
- Code reviewers checking PRs for injection, crypto, or secrets management issues
- DevSecOps engineers integrating security scanning into development workflows
golang-security FAQ
Use golang-security for exploitable vulnerabilities: injection, crypto, secrets, auth, and threat modeling. Use golang-safety for non-exploitable defensive bugs (nil panics, slice aliasing). Use golang-dependency-management for govulncheck scanning and dependency updates.
DREAD scores threats from 1–10 based on Damage, Reproducibility, Exploitability, Affected users, and Discoverability. Critical (8–10) requires immediate fix; High (6–7.9) fix in current sprint; Medium (4–5.9) fix next sprint; Low (1–3.9) fix opportunistically. See the Threat Modeling Guide for detailed methodology.
Always use parameterized queries with database/sql and ? placeholders: `db.QueryRow("SELECT * FROM users WHERE id = ?", userID)`. Never concatenate user input into SQL strings, even if you think it's validated.
Defense in depth means every layer should protect itself. If upstream validation exists, adjust severity downward but still report the finding and document the upstream defense inline. Never skip a finding just because another layer defends it — that layer could be removed or bypassed.
Use Audit mode: launch up to 5 parallel sub-agents covering injection, crypto/secrets, web security, auth/authz, and concurrency/dependencies. Aggregate findings, score with DREAD, and fix each vulnerability in its own isolated worktree for independent, reviewable PRs.
Full instructions (SKILL.md)
Source of truth, from samber/cc-skills-golang.
name: golang-security
description: "Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus gosec SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice aliasing (→ See samber/cc-skills-golang@golang-safety skill), dependency vulnerability scanning with govulncheck (→ See samber/cc-skills-golang@golang-dependency-management skill), or wiring security scanners into CI pipelines (→ See samber/cc-skills-golang@golang-continuous-integration skill)."
user-invocable: true
license: MIT
compatibility: Designed for Claude Code, Codex or similar harness, and for projects using Golang.
metadata:
author: samber
version: "1.2.2"
openclaw:
emoji: "🔒"
homepage: https://github.com/samber/cc-skills-golang
requires:
bins:
- go
- govulncheck
install:
- kind: go
package: golang.org/x/vuln/cmd/govulncheck@latest
bins: [govulncheck]
allowed-tools: Read Edit Write Glob Grep Bash(go:) Bash(golangci-lint:) Bash(git:) Agent WebFetch Bash(govulncheck:) WebSearch AskUserQuestion EnterWorktree ExitWorktree
paths:
- "**/*.go"
Persona: You are a senior Go security engineer. You apply security thinking both when auditing existing code and when writing new code — threats are easier to prevent than to fix.
Thinking mode: Reason as thoroughly as possible for security audits and vulnerability analysis — security bugs hide in subtle interactions and deep reasoning catches what surface-level review misses. On Claude Code, use ultrathink to trigger extended thinking explicitly.
Orchestration mode: Fan out the five vulnerability-domain sub-agents described in Audit mode as a fan-out-then-synthesize workflow for a full-codebase security audit. Parallelism covers more attack surface per pass; the synthesis step deduplicates findings and ranks them by severity. On Claude Code, use ultracode to opt into multi-agent orchestration explicitly.
Modes:
- Review mode — reviewing a PR for security issues. Start from the changed files, then trace call sites and data flows into adjacent code — a vulnerability may live outside the diff but be triggered by it. Sequential.
- Audit mode — full codebase security scan. Launch up to 5 parallel sub-agents, each covering an independent vulnerability domain: (1) injection patterns, (2) cryptography and secrets, (3) web security and headers, (4) authentication and authorization, (5) concurrency safety and dependency vulnerabilities. Aggregate findings, score with DREAD, and report by severity. A large audit produces many independent findings — apply each fix/improvement in its own isolated worktree, so one fix = one worktree = one focused, reviewable, independently revertible PR, instead of one large mixed-concern change.
- Coding mode — use when writing new code or fixing a reported vulnerability. Follow the skill's sequential guidance. Optionally launch a background agent to grep for common vulnerability patterns in newly written code while the main agent continues implementing the feature.
Dependencies:
- govulncheck:
go install golang.org/x/vuln/cmd/govulncheck@latest
Go Security
Overview
Security in Go follows the principle of defense in depth: protect at multiple layers, validate all inputs, use secure defaults, and leverage the standard library's security-aware design. Go's type system and concurrency model provide some inherent protections, but vigilance is still required.
Security Thinking Model
Before writing or reviewing code, ask three questions:
- What are the trust boundaries? — Where does untrusted data enter the system? (HTTP requests, file uploads, environment variables, database rows written by other services)
- What can an attacker control? — Which inputs flow into sensitive operations? (SQL queries, shell commands, HTML output, file paths, cryptographic operations)
- What is the blast radius? — If this defense fails, what's the worst outcome? (Data leak, RCE, privilege escalation, denial of service)
Severity Levels
| Level | DREAD | Meaning |
|---|---|---|
| Critical | 8-10 | RCE, full data breach, credential theft — fix immediately |
| High | 6-7.9 | Auth bypass, significant data exposure, broken crypto — fix in current sprint |
| Medium | 4-5.9 | Limited exposure, session issues, defense weakening — fix in next sprint |
| Low | 1-3.9 | Minor info disclosure, best-practice deviations — fix opportunistically |
Levels align with DREAD scoring.
Research Before Reporting
Before flagging a security issue, trace the full data flow through the codebase — don't assess a code snippet in isolation.
- Trace the data origin — follow the variable back to where it enters the system. Is it user input, a hardcoded constant, or an internal-only value?
- Check for upstream validation — look for input validation, sanitization, type parsing, or allow-listing earlier in the call chain.
- Examine the trust boundary — if the data never crosses a trust boundary (e.g., internal service-to-service with mTLS), the risk profile is different.
- Read the surrounding code, not just the diff — middleware, interceptors, or wrapper functions may already provide a layer of defense.
Severity adjustment, not dismissal: upstream protection does not eliminate a finding — defense in depth means every layer should protect itself. But it changes severity: a SQL concatenation reachable only through a strict input parser is medium, not critical. Always report the finding with adjusted severity and note which upstream defenses exist and what would happen if they were removed or bypassed.
When downgrading or skipping a finding: add a brief inline comment (e.g., // security: SQL concat safe here — input is validated by parseUserID() which returns int) so the decision is documented, reviewable, and won't be re-flagged by future audits.
Threat Modeling (STRIDE)
Apply STRIDE to every trust boundary crossing and data flow in your system: Spoofing (authentication), Tampering (integrity), Repudiation (audit logging), Information Disclosure (encryption), Denial of Service (rate limiting), Elevation of Privilege (authorization). Score each threat using DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability) to prioritize remediation — Critical (8-10) demands immediate action.
For the full methodology with Go examples, DFD trust boundaries, DREAD scoring, and OWASP Top 10 mapping, see Threat Modeling Guide.
Quick Reference
| Severity | Vulnerability | Defense | Standard Library Solution |
|---|---|---|---|
| Critical | SQL Injection | Parameterized queries separate data from code | database/sql with ? placeholders |
| Critical | Command Injection | Pass args separately, never via shell concatenation | exec.Command with separate args |
| High | XSS | Auto-escaping renders user data as text, not HTML/JS | html/template, text/template |
| High | Path Traversal | Scope untrusted file access to an allowed root | Go 1.24+: use os.Root. Pre-Go 1.24: use filepath.IsLocal + filepath.Rel + separator-aware checks; never rely on filepath.Clean + strings.HasPrefix alone. |
| Medium | Timing Attacks | Constant-time comparison avoids byte-by-byte leaks | crypto/subtle.ConstantTimeCompare |
| High | Crypto Issues | Use vetted algorithms; never roll your own | crypto/aes, crypto/rand |
| Medium | HTTP Security | TLS + security headers prevent downgrade attacks | net/http, configure TLSConfig |
| Low | Missing Headers | HSTS, CSP, X-Frame-Options prevent browser attacks | Security headers middleware |
| Medium | Rate Limiting | Rate limits prevent brute-force and resource exhaustion | golang.org/x/time/rate, server timeouts |
| High | Race Conditions | Protect shared state to prevent data corruption | sync.Mutex, channels, avoid shared state |
Detailed Categories
For complete examples, code snippets, and CWE mappings, see:
- Cryptography — Algorithms, key derivation, TLS configuration.
- Injection Vulnerabilities — SQL, command, template injection, XSS, SSRF.
- Filesystem Security — Path traversal, zip bombs, file permissions, symlinks.
- Network/Web Security — SSRF, open redirects, HTTP headers, timing attacks, session fixation.
- Cookie Security — Secure, HttpOnly, SameSite flags.
- Third-Party Data Leaks — Analytics privacy risks, GDPR/CCPA compliance.
- Memory Safety — Integer overflow, memory aliasing,
unsafeusage. - Secrets Management — Hardcoded credentials, env vars, secret managers.
- Logging Security — PII in logs, log injection, sanitization.
- Threat Modeling Guide — STRIDE, DREAD scoring, trust boundaries, OWASP Top 10.
- Security Architecture — Defense-in-depth, Zero Trust, auth patterns, rate limiting, anti-patterns.
Code Review Checklist
For the full security review checklist organized by domain (input handling, database, crypto, web, auth, errors, dependencies, concurrency), see Security Review Checklist — a comprehensive checklist for code review with coverage of all major vulnerability categories.
Tooling & Verification
Static Analysis & Linting
Security-relevant linters: bodyclose, sqlclosecheck, nilerr, errcheck, govet, staticcheck. See the samber/cc-skills-golang@golang-lint skill for configuration and usage.
For deeper security-specific analysis:
# Go security checker (SAST)
go get -tool github.com/securego/gosec/v2/cmd/gosec@latest
go tool gosec ./...
# Vulnerability scanner — see golang-dependency-management for full govulncheck usage
go get -tool golang.org/x/vuln/cmd/govulncheck@latest
go tool govulncheck ./...
To check the known CVEs of a specific module or version without scanning the whole tree (e.g. when vetting a dependency on pkg.go.dev), → See samber/cc-skills-golang@golang-pkg-go-dev skill.
Security Testing
# Race detector
go test -race ./...
# Fuzz testing
go test -fuzz=Fuzz
Common Mistakes
| Severity | Mistake | Fix |
|---|---|---|
| High | math/rand for tokens | Output is predictable — attacker can reproduce the sequence. Use crypto/rand |
| Critical | SQL string concatenation | Attacker can modify query logic. Parameterized queries keep data and code separate |
| Critical | exec.Command("bash -c") | Shell interprets metacharacters (;, |, `). Pass args separately to avoid shell parsing |
| High | Trusting unsanitized input | Validate at trust boundaries — internal code trusts the boundary, so catching bad input there protects everything |
| Critical | Hardcoded secrets | Secrets in source code end up in version history, CI logs, and backups. Use env vars or secret managers |
| Medium | Comparing secrets with == | == short-circuits on first differing byte, leaking timing info. Use crypto/subtle.ConstantTimeCompare |
| Medium | Returning detailed errors | Stack traces and DB errors help attackers map your system. Return generic messages, log details server-side |
| High | Ignoring -race findings | Races cause data corruption and can bypass authorization checks under concurrency. Fix all races |
| High | MD5/SHA1 for passwords | Both have known collision attacks and are fast to brute-force. Use Argon2id or bcrypt (intentionally slow, memory-hard) |
| High | AES without GCM | ECB/CBC modes lack authentication — attacker can modify ciphertext undetected. GCM provides encrypt+authenticate |
| Medium | Binding to 0.0.0.0 | Exposes service to all network interfaces. Bind to specific interface to limit attack surface |
Security Anti-Patterns
| Severity | Anti-Pattern | Why It Fails | Fix |
|---|---|---|---|
| High | Security through obscurity | Hidden URLs are discoverable via fuzzing, logs, or source | Authentication + authorization on all endpoints |
| High | Trusting client headers | X-Forwarded-For, X-Is-Admin are trivially forged | Server-side identity verification |
| High | Client-side authorization | JavaScript checks are bypassed by any HTTP client | Server-side permission checks on every handler |
| High | Shared secrets across envs | Staging breach compromises production | Per-environment secrets via secret manager |
| Critical | Ignoring crypto errors | _, _ = encrypt(data) silently proceeds unencrypted | Always check errors — fail closed, never open |
| Critical | Rolling your own crypto | Custom encryption hasn't been analyzed by cryptographers | Use crypto/aes GCM, golang.org/x/crypto/argon2 |
See Security Architecture for detailed anti-patterns with Go code examples.
Cross-References
See samber/cc-skills-golang@golang-database, samber/cc-skills-golang@golang-safety, samber/cc-skills-golang@golang-observability, samber/cc-skills-golang@golang-continuous-integration skills.
- → See
samber/cc-skills-golang@golang-continuous-integrationskill for automated AI-driven code review in CI using these guidelines
Additional Resources
Related skills
More from samber/cc-skills-golang and the wider catalog.

golang-spf13-cobra
Golang CLI command tree library with subcommands, flags, validation, completions, and doc generation.

golang-spf13-viper
Layered configuration resolution for Go: flags, env vars, files, and defaults in fixed precedence order.

golang-stay-updated
Curated guide to official Go sources, newsletters, communities, influential developers, and blogs for staying current with the Go ecosystem.

golang-stretchr-testify
Comprehensive guide to stretchr/testify for readable assertions, mocks, and test suites in Go.

golang-structs-interfaces
Go struct and interface design patterns — composition, embedding, type assertions, and dependency injection.

golang-swagger
Generate OpenAPI/Swagger docs for Go APIs using swaggo/swag annotations and CLI tooling.