Go Security adversary
Reviews Go trust boundaries, authentication, cryptography, transport security, and secret handling.
Goals
The adversary is designed to produce a small number of high-confidence, actionable findings grounded in concrete repository evidence. Its review should be deterministic where possible, explicit about impact, and quiet when the available evidence does not justify a finding.
Scope
It evaluates changed Go code for command, path, archive, cryptography, TLS, credential, SQL, token, cookie, signature, and debug-surface vulnerabilities.
The complete detector or review inventory is maintained in CHECKS.md.
Boundaries
It owns only this Go specialty. Other Go concerns remain with the corresponding go/* adversaries, and it does not execute or modify the target repository.