← Go: Production EngineeringCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Go: Production Engineering
Snapshot Sep 30, 2026 · 23:15 UTC · version 0.4.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Use for generic Go exploit prevention: authz, SSRF, files, commands, crypto, secrets, and supply chain. Do not use for PCI scope.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 248
},
{
"relative_path": "evals.json",
"size_in_bytes": 11449
},
{
"relative_path": "references/dependency-integrity.md",
"size_in_bytes": 2548
},
{
"relative_path": "references/envelope-encryption-lifecycle.md",
"size_in_bytes": 5036
},
{
"relative_path": "references/process-execution-boundary.md",
"size_in_bytes": 3621
},
{
"relative_path": "references/threat-paths.md",
"size_in_bytes": 747
},
{
"relative_path": "references/trusted-proxy-identity.md",
"size_in_bytes": 4574
},
{
"relative_path": "skill.json",
"size_in_bytes": 4561
}
],
"name": "go-security-hardening",
"skill_md_contents": "---\nname: go-security-hardening\ndescription: \"Use for generic Go exploit prevention: authz, SSRF, files, commands, crypto, secrets, and supply chain. Do not use for PCI scope.\"\nlicense: Apache-2.0\ncompatibility: \"Go 1.24 or newer; security-sensitive APIs and dependency advisories require current verification.\"\n---\n\n# Go security hardening\n\nTrace data and authority from an attacker-controlled input to a protected effect. Do not report a vulnerability without a reachable mechanism.\n\n## Define the trust boundary\n\nIdentify principals, assets, entrypoints, authorization decisions, privileged operations, secrets, persistence, outbound destinations, and audit evidence. Validate syntax and size at parsing; enforce authorization at the resource/action boundary.\n\n## High-risk Go paths\n\n- Build SQL with parameters; identifiers require allowlists or trusted construction.\n- Treat URLs, redirects, DNS, proxies, and resolved IPs as SSRF decisions; prevent access to forbidden networks across redirects and rebinding.\n- Constrain filesystem paths after canonicalization and open through an intended root; consider symlink and race behavior.\n- Avoid shell interpretation. If process execution is necessary, pass fixed executables and structured arguments with a bounded context.\n- Bound decoders, archive expansion, regex work, decompression, multipart data, and recursive structures.\n- Use maintained cryptographic protocols and `crypto/rand`; separate keys from ciphertext and rotate through explicit versions.\n- Keep secrets and sensitive payloads out of errors, logs, metrics, traces, URLs, and idempotency keys.\n\n## Supply chain and artifacts\n\nMinimize dependencies, verify modules and generated inputs, pin CI actions by immutable revisions, scan release archives, and prohibit unreviewed executable resources from published skills. A checksum proves identity, not trustworthiness.\n\nFor dependency or release-pipeline changes, read [references/dependency-integrity.md](references/dependency-integrity.md). Distinguish module authentication, cache verification, vulnerability reachability, source trust, build-input completeness, and artifact provenance; none substitutes for the others.\n\nRead [references/threat-paths.md](references/threat-paths.md) for concrete review paths.\n\nWhen an HTTP backend derives identity, scheme, host, or client certificate from proxy metadata, read [references/trusted-proxy-identity.md](references/trusted-proxy-identity.md). Treat forwarded fields as assertions whose authority comes from an authenticated, non-bypassable proxy path—not from the header name.\n\nWhen designing or rotating encryption at rest, read [references/envelope-encryption-lifecycle.md](references/envelope-encryption-lifecycle.md). Separate KEK rewrap, DEK replacement, and algorithm migration; they repair different risks and require different evidence before old keys retire.\n\nWhen Go launches another program, read [references/process-execution-boundary.md](references/process-execution-boundary.md). Fix executable identity, avoid unintended shell interpretation, minimize inherited environment and descriptors, bound I/O, and own cancellation, reaping, and any descendant process set explicitly. `CommandContext` and `WaitDelay` are lifecycle mechanisms, not a sandbox or proof that grandchildren stopped.\n\n## Output contract\n\nFor each finding, state attacker control, required preconditions, protected effect, impact, and smallest correction. Separate exploitability from defense-in-depth.\n"
}SHA-256 of public snapshot: 444ef6e7b4de9abcc58786ebe089485ad4b7ea2ded0bd6ff1f649dd1d6b4354c