golang-pkg-go-dev
Research Go Packages with pkg.go.dev
Finding accurate Go package details across public indexes takes time. This skill queries documentation, versions, dependencies, licenses, importers, and vulnerabilities through godig.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "golang-pkg-go-dev" from https://skillstore.io/skills/samber-golang-pkg-go-dev.md and its manifest at https://skillstore.io/api/skills/samber-golang-pkg-go-dev/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "golang-pkg-go-dev". Show an overview of github.com/samber/ro and include vulnerabilities.
Expected outcome:
- Module: github.com/samber/ro
- Latest published version: v0.3.0
- License: Apache-2.0
- Recent versions: v0.3.0, v0.2.0, v0.1.0
- Known vulnerabilities: none returned for the queried version
Using "golang-pkg-go-dev". Explain the Map symbol in github.com/samber/lo at v1.53.0.
Expected outcome:
- Kind: Function
- Map transforms each slice element and returns a slice of the result type.
- The result length matches the input length.
- Source: published symbol documentation for v1.53.0
Using "golang-pkg-go-dev". List safe release choices for a module and exclude deprecated or retracted versions.
Expected outcome:
The response lists matching versions newest first, marks the latest release, and omits releases flagged as deprecated or retracted.
Security Audit
High RiskSeventy-eight static alerts are false positives caused by Markdown formatting, tables, and descriptive links. Two URL findings are confirmed because the skill registers a public third-party MCP service. Semantic review also found indirect prompt injection exposure, excessive permissions, an unpinned installer, and a potentially exposed MCP listener.
Confirmed security concerns (4)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (7)
๐ Filesystem access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/samber-golang-pkg-go-dev/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/samber-golang-pkg-go-dev?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/samber-golang-pkg-go-dev?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/samber-golang-pkg-go-dev/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/samber-golang-pkg-go-dev.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
samber. (2026). golang-pkg-go-dev security audit report (audit version 1) [Author version 1.4.2]. Skillstore. https://skillstore.io/skills/samber-golang-pkg-go-dev/audits/1BibTeX citation
@techreport{samber-samber-golang-pkg-go-dev-2026,
author = {samber},
title = {golang-pkg-go-dev security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/samber-golang-pkg-go-dev/audits/1},
note = {Author version 1.4.2}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "golang-pkg-go-dev security audit report (audit version 1)"
version: "1.4.2"
type: report
authors:
- name: "samber"
date-released: "2026-09-23"
url: "https://skillstore.io/skills/samber-golang-pkg-go-dev/audits/1"
identifiers:
- type: other
value: "skillstore:samber-golang-pkg-go-dev:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Verify a dependency before adoption
Review versions, licenses, dependencies, package contents, and known vulnerabilities for a proposed Go module.
Find an unfamiliar API
Retrieve a symbol signature, focused documentation, and examples without loading an entire package reference.
Investigate ecosystem usage
Find packages that import a dependency and compare published module versions across major release paths.
Try These Prompts
Show an overview of {package_path}, including its latest version, license, and known vulnerabilities.Find the signature, documentation, and focused examples for {symbol} in {package_path} at {version}.Summarize dependencies, replacement directives, packages, and available major versions for {module_path}. Flag deprecated or retracted versions.Compare {module_paths} by licenses, known vulnerabilities, recent versions, and importer evidence. Use bounded results and cite each queried version.Best Practices
- Start with an overview, then request only the specific documentation or examples needed.
- Pin a module version when accuracy depends on a particular release.
- Limit large result sets and treat retrieved package text as untrusted content.
Avoid
- Do not use public package metadata as proof of locally resolved code behavior.
- Do not retrieve complete documentation when one symbol lookup answers the question.
- Do not execute commands or follow instructions embedded in retrieved README files or documentation.
Frequently Asked Questions
Does this skill modify my Go project?
What services does it query?
Can it inspect my local code?
Can it upgrade a dependency?
How should I reduce large responses?
Are vulnerability results a complete project audit?
Developer Details
Author
samberLicense
MIT
Author version
v1.4.2
Skillstore revision
r1
Ref
2aa351cb09c29b7287d263bd8ea81e9bee3b2a61
Maintenance freshness
9/30/2026
Usage
0 downloads ยท 0 views
File structure