go-naming — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited go-naming (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Go uses naming to encode visibility (UpperCamelCase = exported, lowerCamelCase = unexported), so naming is load-bearing — not cosmetic. Names should be short, contextual, and non-repetitive. The package name is always present at the call site; pretending otherwise is the single biggest source of bad Go names.
SCREAMING_SNAKE_CASE, no kHungarian. Exceptions: test subtests (TestFoo_BadInput), generated code, cgo.Exported, unexported. Do not invent other conventions.http.HTTPClient is wrong, http.Client is right.i is fine in a 3-line loop; package-level vars need descriptive names.userID, HTTPServer, ParseURL — never userId, HttpServer, ParseUrl.this/self.What are you naming?
├─ Package → lowercase single word, singular, specific (not util/common/helper)
├─ File → lowercase, underscores OK (user_handler.go)
├─ Interface → method + "-er" when single-method (Reader, Closer, Stringer)
├─ Struct/Type → MixedCaps noun (Request, FileHeader)
├─ Constructor → New() if package has one primary type; NewThing() if multiple
├─ Constant → MixedCaps; never ALL_CAPS; role-based not value-based
├─ Enum (iota) → type-prefix + Unknown/Invalid at position 0
├─ Sentinel error → ErrXxx (var ErrNotFound = errors.New("..."))
├─ Error type → XxxError (type PathError struct{})
├─ Boolean field → is/has/can prefix (isReady, hasPerm)
├─ Getter → field name only (Owner()), never GetOwner()
├─ Setter → SetXxx (SetOwner)
├─ Option → WithXxx (WithLogger, WithPort)
├─ Variant → WithContext suffix, In suffix (in-place), Must prefix (panics)
└─ Variable → length proportional to scope distance| Element | Convention | Example |
|---|---|---|
| Package | lowercase, singular | http, tabwriter |
| Exported | UpperCamelCase | ReadAll, HTTPClient |
| Unexported | lowerCamelCase | parseToken, userCount |
| Receiver | 1-2 letters | func (s *Server) |
| Constant | MixedCaps | MaxRetries, defaultTimeout |
| Initialism | uniform case | URL, HTTPServer, xmlParser |
| Sentinel error | Err prefix | ErrNotFound |
| Error type | Error suffix | *PathError |
| Boolean field | is/has/can | isConnected |
| Option func | With + field | WithPort(8080) |
| Format func | f suffix | Errorf, Wrapf |
These are correct but non-obvious — they account for most naming mistakes in code review.
New vs NewThingIf the package exports one primary type, the constructor is New(). Callers write apiclient.New(), not apiclient.NewClient(). Only use NewThing when the package builds several things (http.NewRequest, http.NewServeMux).
Unexported boolean fields use is/has/can. A bare adjective is ambiguous — is connected a method or a field, a state or a verb past tense?
type Conn struct { isOpen bool }
func (c *Conn) IsOpen() bool { return c.isOpen }Including acronyms. Errors get concatenated: fmt.Errorf("parsing token: %w", err) becomes "parsing token: invalid message id". Mid-sentence capitals look wrong. Use "invalid message id" not "invalid message ID".
Sentinel errors should include the package name: errors.New("apiclient: not found").
var s Status is silently 0. If 0 is StatusReady, uninitialised values look intentional. Put StatusUnknown (or Invalid) at iota 0.
type Status int
const (
StatusUnknown Status = iota // zero-value catch
StatusReady
StatusRunning
)t.Run("valid id", ...) // not "Valid ID"
t.Run("empty input", ...)Read references/types-errors-constants.md when naming new struct/interface/enum/error families.
MaxPacketSize // good
userCount // good
parseHTTPResponse // good
MAX_PACKET_SIZE // wrong — Go reserves casing for visibility
max_packet_size // wrong — snake_case
kMaxBufferSize // wrong — HungarianThe package name is always present at the call site.
// In package http
type Client struct{} // not HTTPClient — caller writes http.Client
// In package user
func New() *User // not NewUser — caller writes user.New()
// In package dbpool
type Pool struct{} // not DBPool
type Option func() // not PoolOptionRead references/identifiers-and-scope.md for receivers, variable scope rules, and import aliasing.
Never shadow error, string, len, cap, append, copy, new, make, nil, iota. The compiler allows it; readers and tools do not.
| Mistake | Fix |
|---|---|
MAX_RETRIES = 3 constant | MaxRetries = 3 — MixedCaps |
GetName() string getter | Name() string — Go omits Get |
HttpClient, UserId, ParseUrl | HTTPClient, UserID, ParseURL — uniform initialism case |
this/self receiver | One-letter abbreviation (s for Server) |
util, common, helpers package | Specific name that describes content (stringutil, httpauth) |
user.NewUser() constructor | user.New() — drop the type name |
connected bool field | isConnected bool — prefix reads as a question |
"invalid message ID" error | "invalid message id" — fully lowercase |
StatusReady at iota 0 | Add StatusUnknown at 0 |
userSlice []User | users []User — types do not belong in names |
_ outside of test subtests, generated code, or cgo.Get prefix on getters; setters use Set.Url\|Http\|Json\|Xml\|Id\b in source).ErrXxx; all error types are *XxxError.Unknown/Invalid value at position 0.util, common, helpers, misc.Most rules are mechanical and a linter will catch them in CI:
revive — var-naming, exported, receiver-naming, error-naming.predeclared — flags identifiers that shadow built-ins.errname — enforces ErrXxx / *XxxError.misspell — keeps comments and identifiers consistent.Add them to .golangci.yml and run golangci-lint run in CI.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.