Install
$ agentstack add skill-qte77-claude-code-plugins-reviewing-go ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Review Context
- Changed files: !
git diff --name-only HEAD~1 2>/dev/null || echo "No recent commits" - Staged files: !
git diff --staged --name-only
Code Review
Scope: $ARGUMENTS
Delivers focused, streamlined Go code reviews matching stated task requirements exactly. No over-analysis.
Go Standards
See references/go-best-practices.md for comprehensive Go guidelines.
Workflow
- Read task requirements to understand expected scope
- Check validation passes before detailed review
- Match review depth to task complexity (simple vs complex)
- Validate requirements — does implementation match task scope exactly?
- Issue focused feedback with specific file paths and line numbers
Review Strategy
Simple Tasks (single package): Error handling, requirements match, basic quality
Complex Tasks (multi-package): Above plus architecture, concurrency patterns, context propagation, comprehensive testing
Always: Use existing project patterns, check goroutine lifecycle
Review Checklist
Safety & Security:
- [ ] No ignored errors (every
errhandled or documented) - [ ] SQL queries use parameterized statements
- [ ] JSON decoder uses
DisallowUnknownFields()for untrusted input - [ ] No hardcoded credentials
Requirements Match:
- [ ] Implements exactly what was requested
- [ ] No over-engineering or scope creep
- [ ] Appropriate complexity level
Code Quality:
- [ ] Follows project patterns
- [ ] Error wrapping uses
fmt.Errorf("context: %w", err) - [ ] Interfaces small and defined where consumed
- [ ]
context.Contextpassed as first param, not stored in struct
Concurrency:
- [ ] Every goroutine has a stop signal (
ctx.Done()or channel close) - [ ] Shared state protected by mutex or channels
- [ ] No goroutine leaks
Structural Health:
- [ ] No function exceeds cognitive complexity threshold
- [ ] No copy-paste duplication across methods
- [ ]
internal/used for crate-private packages
Output Standards
Simple Tasks: CRITICAL issues only, clear approval when requirements met Complex Tasks: CRITICAL/WARNINGS/SUGGESTIONS with specific fixes All reviews: Concise, streamlined, no unnecessary complexity analysis
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: qte77
- Source: qte77/claude-code-plugins
- License: Apache-2.0
- Homepage: https://qte77.github.io/claude-code-plugins/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.