go-linters

A development guide for adding custom Go code-analysis linters to gh-aw. A linter is a tool that checks source code for specific mistakes or patterns.

In plain words
What is it for?
Use it to create a Go analyzer, add test fixtures, build the linter runner, run custom linters, and apply coverage-aware performance checks.
Why use it?
It describes where to place the linter, how to test and register it, and how to run the repository's checks consistently.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/github/gh-aw/go-linters
Any agent
npx skills add github/gh-aw --skill go-linters
Clone the repo
git clone --depth 1 https://github.com/github/gh-aw

Made for: Claude Code, Codex.

Per session 17 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 643 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00017 $0.00643
Opus 5 $0.00009 $0.00321
Sonnet 5 $0.00003 $0.00129
Haiku 4.5 $0.00002 $0.00064

Measured 2d ago against content hash fcb4998e73fc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

go-linters scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/skills/go-linters/SKILL.md · 71 lines

How it starts

The opening of the file, as written. The whole thing — 71 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Go Linters

Use this guide when adding a new custom Go analysis linter in this repository.

For PR-driven linter generation (derive a rule from a specific pull request pattern), use .github/skills/pr-to-go-linter/SKILL.md.

Where to add a new linter

  1. Create a new package under pkg/linters/<linter-name>/.
  2. Define an analyzer in that package (exported as Analyzer).
  3. Add tests in the same package using analysistest with fixtures under testdata/src/....
  4. Register the analyzer in cmd/linters/main.go so it runs via the multichecker binary.

Build and test linters

  • Test only your linter package:
    • go test ./pkg/linters/<linter-name>/...
  • Build the custom linter runner:
    • go build ./cmd/linters
  • Run all custom linters across the repo:
    • make golint-custom

make golint-custom builds cmd/linters and runs it against ./cmd/... and ./pkg/....

Coverage-aware perf gating

For linters that flag micro-optimizations (allocation/perf rules), only apply them on lines that tests actually exercise — "hot paths" — rather than on dead or rarely-executed code where the optimization brings no measurable benefit. Use the shared pkg/linters/internal/coverage package:

  1. In your analyzer file, register a -hot-threshold flag in init() (not as a var initializer, to avoid an Analyzer/run/flag initialization cycle):

    var hotThreshold *int
    
    func init() {
        hotThreshold = coverage.RegisterHotThresholdFlag(Analyzer)
    }
    
  2. Immediately before reporting a diagnostic, gate it with coverage.ShouldApply:

    if !coverage.ShouldApply(pass, node.Pos(), *hotThreshold) {
        return
    }
    

coverage.ShouldApply is permissive by default: when no coverage profile is loaded via the GH_AW_LINT_COVERAGE_PROFILE environment variable, or when hot-threshold is 0, it always returns true, preserving pre-coverage-aware behavior. Only wire this into linters whose fix has a genuine performance rationale (extra allocations, O(n²) behavior, etc.) — purely readability/style linters should not be coverage-gated.

Read the full file on GitHub · 71 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 71 lines · 17 tokens per session scan A fcb4998e73fc

Subscribe to this mod's changes

go-linters is a skill published in the GitHub repository github/gh-aw (5,084 stars, last pushed today), licensed MIT. It adds 17 tokens to every session and 643 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

c-github

Interact with GitHub using the gh CLI and jq. Manage PRs, issues, repositories, and Actions workflows. Make raw API calls with gh api for anything not covered by built-in commands.

daxaur/openpaw · 48 tokens

watch-pr

Watch a GitHub pull request for CI status, reviews, comments, merge conflicts, and terminal states using the gh-watch extension. Use when the user wants to monitor a PR, wait for CI, or track PR progress.

justincampbell/gh-watch · 48 tokens

watch-tag

Watch a GitHub repository for new tags using the gh-watch extension. Use when the user wants to be notified when a tag is created, when a release is cut, or when a tag that includes a specific commit appears (e.g. "tell me when my merge ships in a release").

justincampbell/gh-watch · 62 tokens

watch-branch

Watch a GitHub branch for new commits using the gh-watch extension. Use when the user wants to be notified when new commits are pushed to a branch, monitor main for merges, or track branch activity.

justincampbell/gh-watch · 45 tokens

watch-commit

Watch a GitHub commit for CI status changes using the gh-watch extension. Use when the user wants to monitor a commit's CI checks, wait for a build to finish, or track CI progress on a specific SHA.

justincampbell/gh-watch · 48 tokens

update-architecture-docs

Generate or update the architecture documentation in docs/content/architecture/. Use on "update architecture docs", "generate architecture documentation", "regenerate architecture docs", or after any structural change to the codebase.

AlexSkrypnyk/scaffold · 46 tokens