について
このスキルはGoアプリケーションのセキュリティレビューを実施し、入力検証、SQLインジェクション、認証、OWASP Top 10の脆弱性などの領域をカバーします。サービス強化、脆弱性チェック、セキュリティ実装のレビューにご利用ください。依存関係スキャンと並行処理レビューは別スキルで対応するため、本スキルでは対象外です。
クイックインストール
Claude Code
推奨npx skills add eduardo-sl/go-agent-skills -a claude-code/plugin add https://github.com/eduardo-sl/go-agent-skillsgit clone https://github.com/eduardo-sl/go-agent-skills.git ~/.claude/skills/go-security-auditこのコマンドをClaude Codeにコピー&ペーストしてスキルをインストールします
ドキュメント
Go Security Audit
Security is not a feature — it's a property. Every line of code either maintains it or degrades it.
Operating Modes
Pick the mode that matches the request before starting:
- Targeted check — a single concern ("is this query injectable?", "review this auth middleware"). Apply only the relevant sections.
- Diff audit — audit the changed lines of a PR or working tree for every concern below.
- Full audit (default for "security review the service") — sweep the codebase using the parallel passes in "Auditing Large Codebases".
Run the Scanners First
Before manual review, run the automated scanners and fold their output into the findings (skip any that is not installed and note it):
govulncheck ./... # known CVEs actually reachable from your code
gosec ./... # static analysis for insecure patterns
go vet ./... # includes some security-relevant checks
Scanners find the known patterns; the manual passes below find the logic flaws they cannot.
Auditing Large Codebases
Each numbered section below is an independent audit pass. For codebases beyond ~20 files:
- Locate the attack surface first: HTTP/gRPC handlers, CLI entry points, queue consumers, and anything parsing external input.
- Run one pass per concern: (a) input validation + injection, (b) authentication/authorization, (c) secrets + crypto, (d) TLS + security headers + rate limiting, (e) logging hygiene.
- If your environment supports delegating work to parallel sub-agents or tasks, assign each pass to one — the passes don't overlap. Otherwise run them sequentially.
- Every finding must cite
file.go:line, the vulnerable input path, and a concrete fix. Aggregate into one report sorted by severity.
1. Input Validation
NEVER trust user input. Validate at the boundary:
// ✅ Good — validate before use
func (h *Handler) handleCreate(w http.ResponseWriter, r *http.Request) {
// Limit body size
r.Body = http.MaxBytesReader(w, r.Body, 1<<20) // 1 MB
var req CreateRequest
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
respondError(w, http.StatusBadRequest, "invalid JSON")
return
}
if err := validate.Struct(req); err != nil {
respondError(w, http.StatusBadRequest, "validation failed")
return
}
// proceed with validated data
}
String sanitization:
// Sanitize HTML to prevent XSS
import "github.com/microcosm-cc/bluemonday"
p := bluemonday.UGCPolicy()
sanitized := p.Sanitize(userInput)
// Validate email format
import "net/mail"
_, err := mail.ParseAddress(email)
// Validate URLs
u, err := url.Parse(input)
if err != nil || (u.Scheme != "http" && u.Scheme != "https") {
// reject
}
2. SQL Injection Prevention
ALWAYS use parameterized queries:
// ✅ Good — parameterized
row := db.QueryRowContext(ctx,
"SELECT id, name FROM users WHERE email = $1", email)
// ✅ Good — with sqlx named params
query := "SELECT * FROM users WHERE name = :name AND age > :age"
rows, err := db.NamedQueryContext(ctx, query, map[string]interface{}{
"name": name,
"age": minAge,
})
// ❌ CRITICAL — string concatenation = SQL injection
query := "SELECT * FROM users WHERE email = '" + email + "'"
query := fmt.Sprintf("SELECT * FROM users WHERE id = %s", id)
Dynamic queries:
When building dynamic WHERE clauses, use query builders or safe concatenation:
// ✅ Good — safe dynamic query building
var conditions []string
var args []interface{}
argIdx := 1
if name != "" {
conditions = append(conditions, fmt.Sprintf("name = $%d", argIdx))
args = append(args, name)
argIdx++
}
query := "SELECT * FROM users"
if len(conditions) > 0 {
query += " WHERE " + strings.Join(conditions, " AND ")
}
3. Authentication & Authorization
Password handling:
import "golang.org/x/crypto/bcrypt"
// Hash password
hash, err := bcrypt.GenerateFromPassword([]byte(password), bcrypt.DefaultCost)
// Verify password — constant-time comparison built in
err := bcrypt.CompareHashAndPassword(hash, []byte(password))
NEVER store plaintext passwords. NEVER use MD5/SHA for passwords.
JWT validation:
// ✅ Always validate:
// 1. Signature (algorithm must match expectation)
// 2. Expiration (exp claim)
// 3. Issuer (iss claim)
// 4. Audience (aud claim)
// ❌ CRITICAL — never disable signature verification
// ❌ CRITICAL — never accept "alg": "none"
// ❌ CRITICAL — never hardcode signing keys in source code
Authorization middleware:
func RequireRole(role string) func(http.Handler) http.Handler {
return func(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
user := UserFromContext(r.Context())
if user == nil || !user.HasRole(role) {
http.Error(w, "forbidden", http.StatusForbidden)
return
}
next.ServeHTTP(w, r)
})
}
}
4. Secrets Management
Rules:
- 🔴 NEVER hardcode secrets, tokens, or API keys in source code
- 🔴 NEVER commit secrets to git (even in "test" files)
- 🔴 NEVER log secrets, tokens, or passwords
// ✅ Good — from environment
dbURL := os.Getenv("DATABASE_URL")
// ✅ Good — from secrets manager
secret, err := secretsManager.GetSecret(ctx, "api-key")
// ❌ CRITICAL
const apiKey = "sk-1234567890abcdef" // hardcoded secret
Use .gitignore:
.env
*.pem
*.key
credentials.json
Scan for leaked secrets:
# Use gitleaks in CI
gitleaks detect --source=. --verbose
5. HTTP Security Headers
func SecurityHeaders(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("X-Content-Type-Options", "nosniff")
w.Header().Set("X-Frame-Options", "DENY")
w.Header().Set("Content-Security-Policy", "default-src 'self'")
w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains")
w.Header().Set("X-XSS-Protection", "0") // modern browsers handle this
next.ServeHTTP(w, r)
})
}
6. TLS Configuration
tlsConfig := &tls.Config{
MinVersion: tls.VersionTLS12,
CipherSuites: []uint16{
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
},
PreferServerCipherSuites: true,
}
srv := &http.Server{
TLSConfig: tlsConfig,
// ...
}
7. Rate Limiting
import "golang.org/x/time/rate"
type RateLimiter struct {
limiters sync.Map
rate rate.Limit
burst int
}
func (rl *RateLimiter) Allow(key string) bool {
limiter, _ := rl.limiters.LoadOrStore(key,
rate.NewLimiter(rl.rate, rl.burst))
return limiter.(*rate.Limiter).Allow()
}
Apply rate limiting to auth endpoints, public APIs, and any resource-intensive operations.
8. Logging Security
// ❌ CRITICAL — logging sensitive data
log.Printf("user login: email=%s password=%s", email, password)
log.Printf("auth token: %s", token)
log.Printf("request body: %v", req) // may contain secrets
// ✅ Good — redact sensitive fields
log.Printf("user login: email=%s", email)
logger.Info("auth completed", slog.String("user_id", userID))
Security Audit Checklist
Critical (🔴 BLOCKER)
- No SQL injection vectors (all queries parameterized)
- No hardcoded secrets/keys/tokens
- No plaintext password storage
- No disabled TLS certificate verification
- Request body size limited
- JWT signature verified,
alg: nonerejected
Important (🟡 WARNING)
- Input validation on all external data
- Rate limiting on auth and public endpoints
- Security headers set on all responses
- CORS configured restrictively
- Error messages don't leak internals
- Audit logging for auth events
Recommended (🟢 SUGGESTION)
govulncheckin CI pipelinegitleaksfor secret scanning- Structured logging with redaction
- Dependency pinning with verified checksums
GitHub リポジトリ
よくある質問
go-security-audit Skillとは何ですか?
go-security-audit はeduardo-sl が作成した Claude Skillです。Skillは、Claudeが必要に応じて読み込む指示とリソースをまとめ、追加の指示なしで go-security-audit に関連するタスクを実行できるようにします。
go-security-audit をインストールするには?
このページのインストールコマンドを使用してください。go-security-audit をプラグインとして Claude Code に追加するか、リポジトリを skills ディレクトリにクローンし、Claudeを再起動してSkillを読み込みます。
go-security-audit はどのカテゴリに属しますか?
go-security-audit は テスト カテゴリに属します。
go-security-audit は無料で利用できますか?
はい。go-security-audit は AIMCP に掲載されており、無料でインストールできます。
関連スキル
このClaudeスキルは、lm-evaluation-harnessを実行し、MMLUやGSM8Kなど60以上の標準化学術タスクでLLMをベンチマークします。開発者がモデルの品質を比較し、トレーニングの進捗を追跡し、学術的な結果を報告するために設計されています。このツールはHuggingFaceやvLLMモデルを含む様々なバックエンドをサポートしています。
このスキルは、cron式を使用してWorkersをスケジュールするためのCloudflare Cron Triggersの実装に関する包括的な知識を提供します。定期的なタスクの設定、メンテナンスジョブ、自動化されたワークフローの構築を網羅し、無効なcron式やタイムゾーン問題といった一般的な課題への対処法も含みます。開発者はこれを使用して、スケジュールされたハンドラーの設定、cronトリガーのテスト、WorkflowsやGreen Computeとの連携を構成できます。
このClaude Skillは、Playwrightベースのツールキットを提供し、Pythonスクリプトを通じてローカルWebアプリケーションのテストを可能にします。フロントエンドの検証、UIデバッグ、スクリーンショット撮影、ログ表示を実現し、サーバーライフサイクルを管理します。ブラウザ自動化タスクにご利用いただけますが、コンテキストの汚染を避けるため、スクリプトのソースコードを読むのではなく直接実行してください。
このスキルは、開発者がテストの合格を確認し、構造化された統合オプションを提示することで、完成した作業を仕上げることを支援します。実装が完了した後のマージ、PR作成、ブランチの整理といったワークフローを案内します。コードが準備できてテスト済みの際に使用し、開発プロセスを体系的に完了させましょう。
