Go source review
SkillDatabases & dataSecurity review of Go code, dangerous sinks and web-framework pitfalls. Load when reviewing a Go codebase/PR, on .go source in scope, or "review this Go". Signals: go.mod, net/http, os/exec, text/template, database/sql, gin/echo/fiber.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Go source review skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-go/SKILL.md and read by ahel’s review.
When it applies
Reviewing Go source (an API, a CLI, a microservice). Go is memory-safe, so the bugs are logic and injection: command exec, the wrong template package, string-built SQL, and path/SSRF handling.
Why it works
Go's stdlib gives a safe and an unsafe option side by side (html/template vs text/template;
parameterised db.Query(?, x) vs fmt.Sprintf into a query). Reviews find code that reached for the
unsafe one, or that shells out with sh -c.
Sinks & patterns (grep, then trace to user input)
- Command exec:
exec.Command("sh","-c", …)/exec.CommandContextwith concatenated input (safe form passes args separately — flag thesh -cvariant). - XSS:
text/templateused to render HTML (no auto-escaping); manualw.Write([]byte(userHTML)). - SQLi:
fmt.Sprintf/string concat intodb.Query/db.Execinstead of placeholders. - Path traversal:
filepath.Join(base, userInput)withoutfilepath.Clean+ prefix check;http.ServeFilewith user paths. - SSRF:
http.Get/http.NewRequeston user-supplied URLs; missing host allowlist. - Other:
text/template/html/templateinjection from user-controlled template strings, unvalidatedUnmarshalinto structs (mass assignment),unsafepointer use, weakmath/randfor tokens (usecrypto/rand).
Framework specifics
- gin/echo/fiber:
c.Param/c.Query/c.Bindsources; check bound structs for mass assignment and missing auth middleware on state-changing routes. - Templates: confirm
html/template(nottext/template) for anything rendered to a browser.
Method
- Run
gosecandgovulncheckfor a first pass; treat as leads, not verdicts. rg 'exec.Command|text/template|Sprintf.*Query|filepath.Join'and trace to request input.- Check auth/authorization middleware coverage on each route group.
- Confirm exploitable classes with the matching runtime skill.
Gotchas
exec.Command(name, arg1, arg2)(no shell) is safe — only thesh -c "...user..."form injects.html/templatecontext-escapes; the bug is usually usingtext/templateby mistake.- Errors ignored with
_can hide security-relevant failures (e.g. an auth check's error).
References
Go security best practices; gosec rule set; OWASP Go SCP; govulncheck (known-vuln deps).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-go- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · andrewnggirl
The pick for Cryptocrypto-tools
Skill · lingbol088-spec
The pick for Cryptoaudit-dependencies
Skill · stbenjam
The pick for Dependenciesreview-dependencies
Skill · tobihagemann
The pick for Dependenciesowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)