← Files Go: FintechARCHIVED FILE
skills/go-fintech-security-compliance/skill.json
3.51 KB · Oct 5, 2026 · 18:32 UTC
{"schema_version":2,"collection":"fintech-skills-for-go","display_name":"Go Fintech Security and Compliance","short_description":"Constrain financial trust and data scope","default_prompt":"Use $go-fintech-security-compliance to engineer this Go fintech trust boundary.","version":"0.2.0","maturity":"beta","category":"compliance","risk_domains":["security","privacy","compliance","auditability"],"tags":["go","fintech","pci-dss","sanctions","screening","authorization","audit","tokenization","webhooks","signatures"],"go_versions":{"minimum":"1.24","guidance":["1.25","1.26"]},"claim_ids":["fin-data-boundaries","fin-sanctions-screening-control","fin-webhook-authenticity"],"relations":{"complements":["go-security-hardening","review-go-fintech-change","go-payment-lifecycles","go-financial-idempotency"],"overlaps":[]},"compatibility_evidence":[{"client":"codex","level":"behaviorally-benchmarked","contract":"OpenAI skill plus agents/openai.yaml and committed eval artifacts","verified_on":"2026-08-18"},{"client":"claude-code","level":"structurally-compatible","contract":"Claude plugin skill layout and manifest validation","verified_on":"2026-08-18"},{"client":"cursor","level":"structurally-compatible","contract":"Agent Plugin and .cursor/skills layout validation","verified_on":"2026-08-18"},{"client":"opencode","level":"structurally-compatible","contract":".agents/skills layout and portable frontmatter validation","verified_on":"2026-08-18"}],"source_provenance":{"method":"independent-rewrite-from-primary-evidence","reference_repositories":[],"corpus_lock":"research/corpus-lock.json"},"sources":[{"title":"PCI Data Security Standard","url":"https://www.pcisecuritystandards.org/document_library/","publisher":"PCI Security Standards Council","kind":"primary","verified_on":"2026-08-24","supports":["PCI DSS v4.0.1","account data","sensitive authentication data","security controls","scope"]},{"title":"NIST SP 800-63B","url":"https://pages.nist.gov/800-63-4/sp800-63b.html","publisher":"NIST","kind":"normative","verified_on":"2026-08-18","supports":["authentication assurance","authenticators"]},{"title":"A Framework for OFAC Compliance Commitments","url":"https://ofac.treasury.gov/media/16331/download","publisher":"U.S. Department of the Treasury, OFAC","kind":"primary","verified_on":"2026-08-24","supports":["risk-based sanctions program","screening controls","list updates","due diligence","testing and audit"]},{"title":"False Hit Lists Guidance","url":"https://ofac.treasury.gov/system/files/126/false_hit.pdf","publisher":"U.S. Department of the Treasury, OFAC","kind":"primary","verified_on":"2026-08-24","supports":["false-hit oversight","periodic reassessment","invalidation after list or subject changes"]},{"title":"Stripe webhooks","url":"https://docs.stripe.com/webhooks","publisher":"Stripe","kind":"primary","verified_on":"2026-08-24","supports":["raw-body signature verification","endpoint secrets","timestamp replay mitigation","duplicate and unordered events"]},{"title":"Adyen: Verify HMAC signatures","url":"https://docs.adyen.com/development-resources/webhooks/secure-webhooks/verify-hmac-signatures","publisher":"Adyen","kind":"primary","verified_on":"2026-08-24","supports":["webhook-specific signed material","endpoint and environment keys","rotation overlap"]},{"title":"PayPal: Verify webhook signature","url":"https://developer.paypal.com/api/webhooks/v1/verify-webhook-signature-post/","publisher":"PayPal","kind":"primary","verified_on":"2026-08-24","supports":["transmission evidence","webhook identity","remote signature verification"]}]}
SHA-256: 6da88eeba633144604ccd853f00d8f8fe52d4ea9f2a39c849cb2231beffb06fa