go-context — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited go-context (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
context.Context carries the cancellation, deadline, and request-scoped values for a single unit of work. Pass it explicitly through the entire call chain — never store it, never replace it with Background() mid-flight, never use it as a side-channel for ordinary parameters.
ctx context.Context. No exceptions outside interface stubs imposed by external APIs.context.Background() inside a request path.WithCancel/WithTimeout/WithDeadline, unless ownership is explicitly transferred.Pick the most explicit option that fits — context values are the last resort.
| Option | Use for | Why |
|---|---|---|
| Function parameter | Anything the function needs to do its job | Type-checked, visible at call site |
| Method receiver | State that belongs to the type | Already in scope |
| Package-level config | Process-wide, immutable | One owner, no hidden flow |
context.Value | Request-scoped metadata that crosses layers without being a function arg | Untyped — use sparingly |
Read references/values-and-keys.md for the unexported-key pattern, typed accessors, and OpenTelemetry/trace propagation.
| Situation | Use |
|---|---|
main, init, top-level test | context.Background() |
| Placeholder while plumbing is incomplete | context.TODO() |
| Inside an HTTP handler | r.Context() |
| Need manual cancellation | context.WithCancel(parent) |
| Need a deadline / timeout | context.WithTimeout(parent, d) / WithDeadline |
| Background work that must outlive the request (Go 1.21+) | context.WithoutCancel(parent) |
// Bad — breaks the chain, downstream cannot be cancelled
func (s *OrderService) Create(ctx context.Context, o Order) error {
return s.db.ExecContext(context.Background(), insertSQL, o.ID)
}
// Good — same ctx flows HTTP handler -> service -> DB -> external API
func (s *OrderService) Create(ctx context.Context, o Order) error {
return s.db.ExecContext(ctx, insertSQL, o.ID)
}ctx, cancel := context.WithTimeout(ctx, 5*time.Second)
defer cancel() // release resources even on the happy path
select {
case <-ctx.Done():
return ctx.Err()
case res := <-doAsync(ctx):
return res
}Read references/cancellation-and-deadlines.md forWithoutCancel,AfterFunc, and long-running goroutine cancellation patterns.
Context in Custom Types// Bad — pollutes the standard signature
type MyCtx interface {
context.Context
UserID() string
}
// Good — keep the signature standard, extract via helper
func UserIDFrom(ctx context.Context) (string, bool) { /* ... */ }Most context mistakes are mechanical and a linter will catch them in CI before review:
govet -vet=context — flags non-first context.Context parameters and lost cancels.staticcheck SA1012 — calls passing nil context.contextcheck (golangci-lint) — verifies downstream calls propagate ctx.noctx — flags HTTP/SQL APIs called without their *Context variant.Run golangci-lint run --enable=contextcheck,noctx,staticcheck in CI for any project that exposes context.Context.
| Anti-pattern | Why it hurts | Do this instead |
|---|---|---|
ctx context.Context stored on a struct field | Lifetime becomes invisible; outlives the request | Pass ctx to each method |
context.Background() mid-call | Cancellation chain breaks; goroutines leak | Use the caller's ctx |
ctx.Value("user-id") with a string key | Cross-package collisions, no type safety | Unexported key type + typed getter |
Passing nil as a context | Panics on Done() / Value() | Use context.TODO() while plumbing |
WithTimeout without defer cancel() | Leaks the timer until parent finishes | defer cancel() on the next line |
Custom MyContext interface | Breaks every standard signature | Keep context.Context, extract with helpers |
ctx-aware API takes ctx context.Context as its first parameter.context.Context field on any struct (search: ctx\s+context\.Context inside type ... struct).WithCancel/WithTimeout/WithDeadline is followed by defer cancel() on the next line.context.Background() or context.TODO() calls inside request handlers.golangci-lint run --enable=contextcheck,noctx passes.WithoutCancel, AfterFunc, goroutine cancellationNewRequestWithContext, QueryContext/ExecContext~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.