{"id":19123,"plugin_id":"plugins_6a92c6b7e7948191ab7802aa05afc6f7","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:18.471Z","digest":"444ef6e7b4de9abcc58786ebe089485ad4b7ea2ded0bd6ff1f649dd1d6b4354c","against":null,"payload":{"description":"Use for generic Go exploit prevention: authz, SSRF, files, commands, crypto, secrets, and supply chain. Do not use for PCI scope.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":248},{"relative_path":"evals.json","size_in_bytes":11449},{"relative_path":"references/dependency-integrity.md","size_in_bytes":2548},{"relative_path":"references/envelope-encryption-lifecycle.md","size_in_bytes":5036},{"relative_path":"references/process-execution-boundary.md","size_in_bytes":3621},{"relative_path":"references/threat-paths.md","size_in_bytes":747},{"relative_path":"references/trusted-proxy-identity.md","size_in_bytes":4574},{"relative_path":"skill.json","size_in_bytes":4561}],"name":"go-security-hardening","skill_md_contents":"---\nname: go-security-hardening\ndescription: \"Use for generic Go exploit prevention: authz, SSRF, files, commands, crypto, secrets, and supply chain. Do not use for PCI scope.\"\nlicense: Apache-2.0\ncompatibility: \"Go 1.24 or newer; security-sensitive APIs and dependency advisories require current verification.\"\n---\n\n# Go security hardening\n\nTrace data and authority from an attacker-controlled input to a protected effect. Do not report a vulnerability without a reachable mechanism.\n\n## Define the trust boundary\n\nIdentify principals, assets, entrypoints, authorization decisions, privileged operations, secrets, persistence, outbound destinations, and audit evidence. Validate syntax and size at parsing; enforce authorization at the resource/action boundary.\n\n## High-risk Go paths\n\n- Build SQL with parameters; identifiers require allowlists or trusted construction.\n- Treat URLs, redirects, DNS, proxies, and resolved IPs as SSRF decisions; prevent access to forbidden networks across redirects and rebinding.\n- Constrain filesystem paths after canonicalization and open through an intended root; consider symlink and race behavior.\n- Avoid shell interpretation. If process execution is necessary, pass fixed executables and structured arguments with a bounded context.\n- Bound decoders, archive expansion, regex work, decompression, multipart data, and recursive structures.\n- Use maintained cryptographic protocols and `crypto/rand`; separate keys from ciphertext and rotate through explicit versions.\n- Keep secrets and sensitive payloads out of errors, logs, metrics, traces, URLs, and idempotency keys.\n\n## Supply chain and artifacts\n\nMinimize dependencies, verify modules and generated inputs, pin CI actions by immutable revisions, scan release archives, and prohibit unreviewed executable resources from published skills. A checksum proves identity, not trustworthiness.\n\nFor dependency or release-pipeline changes, read [references/dependency-integrity.md](references/dependency-integrity.md). Distinguish module authentication, cache verification, vulnerability reachability, source trust, build-input completeness, and artifact provenance; none substitutes for the others.\n\nRead [references/threat-paths.md](references/threat-paths.md) for concrete review paths.\n\nWhen an HTTP backend derives identity, scheme, host, or client certificate from proxy metadata, read [references/trusted-proxy-identity.md](references/trusted-proxy-identity.md). Treat forwarded fields as assertions whose authority comes from an authenticated, non-bypassable proxy path—not from the header name.\n\nWhen designing or rotating encryption at rest, read [references/envelope-encryption-lifecycle.md](references/envelope-encryption-lifecycle.md). Separate KEK rewrap, DEK replacement, and algorithm migration; they repair different risks and require different evidence before old keys retire.\n\nWhen Go launches another program, read [references/process-execution-boundary.md](references/process-execution-boundary.md). Fix executable identity, avoid unintended shell interpretation, minimize inherited environment and descriptors, bound I/O, and own cancellation, reaping, and any descendant process set explicitly. `CommandContext` and `WaitDelay` are lifecycle mechanisms, not a sandbox or proof that grandchildren stopped.\n\n## Output contract\n\nFor each finding, state attacker control, required preconditions, protected effect, impact, and smallest correction. Separate exploitability from defense-in-depth.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}