new-feature-go — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited new-feature-go (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Do not open any file for editing until all 6 steps are completed.
Write the surface in plain text first:
Feature name: credits
Public types: *Service (concrete), Repository (interface, lives next to Service)
Methods: Charge(ctx, userID, amount, idem) (string, error)
Confirm(ctx, holdID) error
Refund(ctx, holdID) error
Errors: ErrInsufficientFunds (sentinel), *ValidationError (typed)
Single-writer for: Repository.Hold — only Service.Charge calls itIf the public surface needs more than 5-6 methods, the package is doing too much — split it (Principle E2).
| Scope | Location |
|---|---|
| Public library others import via go.mod | pkg/<name>/ |
| Private to this service | internal/<name>/ (default) |
| HTTP wiring / handlers | internal/server/ |
| Cross-cutting helpers (genuine ones) | internal/<purpose>/ (e.g. internal/httpclient) |
| Binary entry point | cmd/<binary>/main.go |
Forbidden package names: utils, helpers, common, shared, lib, misc. Pick a name that says what the package does.
1. Errors → internal/<name>/errors.go (sentinels + typed)
2. Repository iface → internal/<name>/repository.go (smallest set of methods)
3. Repository impl → internal/<name>/repository.go (MemoryRepo for tests, SQLRepo for prod)
4. Service struct → internal/<name>/service.go (concrete, accepts Repository)
5. Service tests → internal/<name>/service_test.go (table-driven, t.Run)
6. Handler → internal/server/handlers.go (defines tiny consumer interface)
7. Wiring → cmd/api/main.go (constructor injection)Critical rules during build:
*Service (concrete). Handlers accept the smallest interface they need (Principle F1).context.Context is the first parameter of every I/O method (Principle F2).panic'd. Wrap with %w (Principle F3).httpclient.Get("<provider>") — never use http.DefaultClient (Principle F4).Every I/O method should log with context:
s.log.InfoContext(ctx, "credits.charge",
"user_id", userID,
"amount", amount.String(),
"hold_id", holdID,
)InfoContext/ErrorContext (Go 1.21+) attach the request ID and other context-scoped values automatically if your slog handler is wired to read them. Don't use fmt.Println. Don't use log.Printf. (Principle F6.)
func TestService_Charge(t *testing.T) {
cases := []struct {
name string
balance decimal.Decimal
amount decimal.Decimal
wantErr error
}{
{"happy path", dec("10.00"), dec("4.00"), nil},
{"insufficient", dec("3.00"), dec("4.00"), ErrInsufficientFunds},
}
for _, tc := range cases {
tc := tc // capture
t.Run(tc.name, func(t *testing.T) {
t.Parallel()
svc := newTestService(t, tc.balance)
_, err := svc.Charge(context.Background(), "u-1", tc.amount, "idem-"+tc.name)
if !errors.Is(err, tc.wantErr) {
t.Fatalf("got %v, want %v", err, tc.wantErr)
}
})
}
}For typed errors, use errors.As:
var ve *ValidationError
if !errors.As(err, &ve) { t.Fatalf("expected ValidationError, got %v", err) }# E2: no forbidden package names
find . -type d \( -name utils -o -name helpers -o -name common -o -name shared \) -not -path "./vendor/*"
# E4: file size cap
find . -name "*.go" -not -path "./vendor/*" | xargs wc -l | sort -rn | head
# F1: services return concrete structs
grep -rn "func New[A-Z].*\binterface\b" internal/ # should be empty
# F2: context.Context is first param of I/O methods
grep -rn "func.*\b(Charge|Hold|Refund|Get|List|Create|Update|Delete)\b\(" internal/ | grep -v "ctx context\.Context"
# F3: no panic in production code
grep -rn "panic(" internal/ --include="*.go" | grep -v "_test.go\|recover"
# F4: no http.DefaultClient
grep -rn "http\.DefaultClient" internal/
# F6: no fmt.Println in production code
grep -rn "fmt\.Println\|log\.Printf" internal/ --include="*.go" | grep -v "_test.go"
# F9: single-writer (e.g. repo.Hold called from one place)
grep -rln "\.Hold(" internal/ --include="*.go" | grep -v "_test.go\|repository.go"
# expected: only internal/credits/service.gogo vet ./...
go test ./... -raceBoth must exit 0.
utils, helpers)*Servicecontext.Context is the first parameter of every I/O method%w; sentinels for stable conditions, typed errors for rich infohttpclient.Get(provider) used for any external HTTP — never http.DefaultClientslog with context, no fmt.Printlnt.Rungo vet ./... && go test ./... -race exits 0~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.