SKILL·3C21DE

go-code-review

eduardo-sl
Updated Yesterday
63
9
63
View on GitHub
Testingtesting

About

This skill provides a structured checklist for reviewing Go code, focusing on idiomatic patterns, error handling, and test coverage. It operates in modes for reviewing diffs (like PRs) or full files/packages. Use it for general code quality reviews, not for security or performance-specific audits.

Quick Install

Claude Code

Recommended
Primary
npx skills add eduardo-sl/go-agent-skills -a claude-code
Plugin CommandAlternative
/plugin add https://github.com/eduardo-sl/go-agent-skills
Git CloneAlternative
git clone https://github.com/eduardo-sl/go-agent-skills.git ~/.claude/skills/go-code-review

Copy and paste this command in Claude Code to install this skill

Documentation

Go Code Review

Structured code review process for Go. Reviews should be constructive, specific, and cite the relevant principle behind each finding.

Operating Modes

Pick the mode that matches the request before starting:

  • Diff review (default) — review only the changed lines plus enough surrounding context to judge them. Use for PRs and working-tree changes.
  • File/package review — review the named files or packages in full, including their tests.
  • Full audit — sweep the entire codebase. Use the strategy in "Auditing Large Codebases" below and aggregate everything into one report.

Review Process

Execute these steps in order. For each finding, classify severity:

  • 🔴 BLOCKER — Must fix before merge. Correctness, data loss, security.
  • 🟡 WARNING — Should fix. Maintainability, idiomatic Go, clarity.
  • 🟢 SUGGESTION — Consider improving. Style, naming, documentation.

0. Run the Toolchain First

Before reading code manually, let the tools catch the mechanical issues (skip any tool that is not installed and note it in the report):

go build ./...          # it must compile
go vet ./...            # suspicious constructs
golangci-lint run       # if the repo has a config
go test -race ./...     # tests pass, no data races

Report tool findings alongside manual findings — a failing go vet is an automatic 🔴 BLOCKER. Never report an issue a tool already proves absent.

1. Correctness & Safety

Error Handling

  • Every error is checked. No blank identifier _ discarding errors silently.
  • Errors are wrapped with context: fmt.Errorf("fetch user %d: %w", id, err).
  • Error values compared with errors.Is() / errors.As(), never ==.
  • No panic outside of init() or truly unrecoverable situations.
  • Errors handled exactly once — no log-and-return patterns.

Nil Safety

  • Pointer receivers checked before dereference when nil is a valid state.
  • Map reads guarded or use comma-ok idiom.
  • Channel operations consider closed/nil channels.
  • Slice operations check bounds where relevant.

Concurrency

  • Shared mutable state protected by sync.Mutex or channels.
  • No goroutine leaks — every goroutine has a clear termination path.
  • Context propagation: all blocking calls accept and respect context.Context.
  • sync.WaitGroup or errgroup.Group used for goroutine lifecycle.

2. API Design

  • Exported functions have doc comments starting with the function name.
  • Accept interfaces, return concrete types.
  • Use functional options (WithTimeout(d)) over config structs for optional params.
  • Context is always the first parameter: func Foo(ctx context.Context, ...).
  • Return error as the last return value.
  • Avoid bool parameters — prefer named types or options.

3. Idiomatic Go

  • Uses := for local variables, var for zero-value intent.
  • No unnecessary else after return/continue/break.
  • Guard clauses and early returns reduce nesting.
  • defer used for cleanup, placed right after resource acquisition.
  • range used over manual index iteration where appropriate.
  • Struct literals use field names.
  • Interfaces defined at consumer, not producer.

4. Package Structure

  • Package names are short, lowercase, singular nouns.
  • No circular dependencies between packages.
  • internal/ used for non-public packages.
  • cmd/ contains main packages, one per binary.
  • Clear separation of concerns — no god packages.

5. Testing

  • Test functions follow TestXxx naming convention.
  • Table-driven tests used for multiple input/output combinations.
  • Test helpers use t.Helper() for clean stack traces.
  • No test logic in init() — use TestMain when needed.
  • Tests use testify/assert or testify/require consistently, or stdlib only.
  • Edge cases covered: empty input, nil, zero values, max values.
  • t.Parallel() used where safe.

6. Documentation

  • All exported types, functions, and constants have doc comments.
  • Doc comments start with the name of the entity.
  • Package-level doc comment in doc.go for non-trivial packages.
  • Complex algorithms or business logic have inline comments explaining why.

7. Dependencies

  • go.mod has no replace directives in committed code (except monorepos).
  • No unused dependencies.
  • Dependencies are from well-maintained, reputable sources.
  • Indirect dependencies are understood and acceptable.

Auditing Large Codebases

When the scope exceeds ~20 files, do not read everything in one linear pass. Split the audit into independent passes:

  1. Enumerate packages (go list ./...) and group them by layer (handlers, services, stores, shared libraries).
  2. Run one focused pass per concern from sections 1-7 (correctness, API design, idioms, structure, testing, docs, dependencies).
  3. If your environment supports delegating work to parallel sub-agents or tasks, assign each pass to one — they are independent by design. Otherwise run them sequentially, one concern at a time.
  4. Require every finding to cite file.go:line and severity so the final aggregation is mechanical: merge, deduplicate, sort by severity.

Review Output Format

## Code Review Summary

**Files reviewed:** <list>
**Overall assessment:** APPROVE | REQUEST CHANGES | COMMENT

### Findings

#### 🔴 BLOCKER: <title>
- **File:** `path/to/file.go:42`
- **Issue:** <what is wrong>
- **Why:** <which principle or guideline>
- **Fix:** <concrete suggestion>

#### 🟡 WARNING: <title>
...

#### 🟢 SUGGESTION: <title>
...

### What's Done Well
<genuine positive observations — always include at least one>

GitHub Repository

eduardo-sl/go-agent-skills
Path: skills/(code-quality)/go-code-review
0
FAQ

Frequently asked questions

What is the go-code-review skill?

go-code-review is a Claude Skill by eduardo-sl. Skills package instructions and resources that Claude loads on demand, so Claude can perform go-code-review-related tasks without extra prompting.

How do I install go-code-review?

Use the install commands on this page: add go-code-review to Claude Code as a plugin, or clone its repository into your skills directory, then restart Claude so it picks up the skill.

What category does go-code-review belong to?

go-code-review is in the Testing category, tagged testing.

Is go-code-review free to use?

Yes. go-code-review is listed on AIMCP and free to install.

Related Skills

evaluating-llms-harness
Testing

This Claude Skill runs the lm-evaluation-harness to benchmark LLMs across 60+ standardized academic tasks like MMLU and GSM8K. It's designed for developers to compare model quality, track training progress, or report academic results. The tool supports various backends including HuggingFace and vLLM models.

View skill
cloudflare-cron-triggers
Testing

This skill provides comprehensive knowledge for implementing Cloudflare Cron Triggers to schedule Workers using cron expressions. It covers setting up periodic tasks, maintenance jobs, and automated workflows while handling common issues like invalid cron expressions and timezone problems. Developers can use it for configuring scheduled handlers, testing cron triggers, and integrating with Workflows and Green Compute.

View skill
webapp-testing
Testing

This Claude Skill provides a Playwright-based toolkit for testing local web applications through Python scripts. It enables frontend verification, UI debugging, screenshot capture, and log viewing while managing server lifecycles. Use it for browser automation tasks but run scripts directly rather than reading their source code to avoid context pollution.

View skill
finishing-a-development-branch
Testing

This skill helps developers complete finished work by verifying tests pass and then presenting structured integration options. It guides the workflow for merging, creating PRs, or cleaning up branches after implementation is done. Use it when your code is ready and tested to systematically finalize the development process.

View skill