Install
$ agentstack add skill-alexei-led-cc-thingz-writing-go ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Go Development
Use only for Go modules. Follow the module's target Go version.
Read First
Read [principles.md](references/principles.md) before writing, changing, or reviewing Go code. Read conditional references only when the change touches that area.
Conditional References
- [patterns.md](references/patterns.md) — package layout, interfaces, errors, HTTP/service boundaries, concurrency, comments.
- [testing.md](references/testing.md) — adding or reshaping Go tests; keep the local test loop fast.
- [linting.md](references/linting.md) — changing lint config, lint commands, or slow lint workflows.
- [cli.md](references/cli.md) — writing or changing Go CLIs.
Comments
- Use doc comments for exported declarations. Start with the identifier and end with a period.
- Comment non-trivial unexported declarations only when their contract is not obvious.
- Add implementation comments only for non-obvious constraints, invariants, side effects, tradeoffs, or tuning decisions.
- Keep comments short. Move longer rationale to docs, issue links, or design notes.
- Do not comment obvious code or restate names and types.
- Keep tests readable without comments; add one only for unobvious fixtures, timing, concurrency, or regression context.
Version-Gated APIs
- Confirm
go.mod,toolchain, CI, and nearby code before using version-specific APIs. - Go 1.25+: use
sync.WaitGroup.Gowhen no error propagation is needed. - Use existing
errgroupfor goroutine errors or shared cancellation; add it only when the dependency is justified. - Go 1.25+: use
testing/synctestfor deterministic concurrent tests when available. - Go 1.25+: prefer stdlib
crypto/hpkeandtesting/cryptotestover third-party code when they fit. - Treat
encoding/json/v2as experimental unless the project opts intoGOEXPERIMENT=jsonv2. - Go 1.26+: use
new(expr)only when clearer than a local variable, composite literal, or address expression. - Go 1.26+: keep recursive type constraints in generic libraries; keep business logic concrete.
Verification
Run focused package tests and lint while editing, then the project-configured build, tests, lint, vet, and formatting checks before final output. Add race or concurrency-specific checks when the change touches goroutines, shared state, timers, or channels.
If a check is unavailable, state that and run the closest configured gate. If a check fails, quote the failure, diagnose the cause, fix one issue, and rerun the relevant check.
Failure Cases
- No clear Go root: locate
go.modbefore choosing files, commands, or import paths. - Unknown Go target: inspect
go.mod,toolchain, CI, and lockfiles before using version-specific APIs. - New dependency requested: confirm stdlib or existing dependencies cannot meet the requirement.
- Broad or risky edit: state the risk and ask before acting. Do not run destructive commands.
Final Response
Include:
- changed files
- checks run and results
- checks skipped with reasons
- remaining risks or follow-ups
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: alexei-led
- Source: alexei-led/cc-thingz
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.