zog

zog is a skill for Claude Code from xobotyi/cc-foundry. It costs 45 tokens per session (3,023 once invoked), scanned B, original, MIT.

A guide for using Zog, a Go library for checking whether input data matches a defined schema. It explains schema structure, parsing, validation, defaults, errors, tests, and web-related adapters.

In plain words
What is it for?
Use it when defining or reviewing Go validation schemas, handling JSON, form, query, or environment input, writing tests, or diagnosing validation errors.
Why use it?
It highlights differences from similarly named JavaScript tools and helps avoid schemas that compile but interpret missing fields or input names incorrectly.

Skill for Claude Code

Written for Claude Code: when-to-use in frontmatter. Also seen: mentions Claude Code.

Part of the golang plugin — 4 skills shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/xobotyi/cc-foundry/zog
Any agent
npx skills add xobotyi/cc-foundry --skill zog
Clone the repo
git clone --depth 1 https://github.com/xobotyi/cc-foundry

Made for: Claude Code.

Or install golang, the plugin that ships this one along with the rest of its 4 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for zog

README.md
[![agentmods](https://agentmods.dev/badge/skills/xobotyi/cc-foundry/zog.svg)](https://agentmods.dev/skills/xobotyi/cc-foundry/zog)
Your own site
<a href="https://agentmods.dev/skills/xobotyi/cc-foundry/zog"><img src="https://agentmods.dev/badge/skills/xobotyi/cc-foundry/zog.svg" alt="Measured on agentmods" height="20"></a>
Per session 45 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,023 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00045 $0.03023
Opus 5 $0.00023 $0.01511
Sonnet 5 $0.00009 $0.00605
Haiku 4.5 $0.00005 $0.00302

Measured 6d ago against content hash 715be7da2655, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade B, and why

zog scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Strips warnings and disclaimersmediumAnti-refusal

Omitting safety caveats hides risk from the user and is a common jailbreak preamble.

When **reviewing** Zog, cite the violation and show the fix inline. Do not lecture. Treat a `.Required()` on a value
plugins/golang/skills/zog/SKILL.md · 186 lines

How it starts

The opening of the file, as written. The whole thing — 186 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Zog is a Zod-shaped API over Go semantics, and the two disagree in ways that still compile. Import as z "github.com/Oudwins/zog". Three biases decide most calls:

  • A remembered Zod default is a defect until checked. Fields are optional by default, z.Enum does not exist, and a schema key names a Go struct field rather than an input key.
  • Parse and Validate disagree about what missing means, and that disagreement decides which tests in a chain run at all.
  • Zog panics on a schema its author built wrong, and never on input data. A panic is a defect in the schema definition, fixed there.

Schema Shape

  • A z.Shape key names a Go struct field, never an input key. The first letter is case-corrected, so "name" and "Name" both bind to Name. A key matching no field panics with Struct Schema Definition Error ... missing expected schema key.
  • Struct tags map input keys and nothing else. Resolution runs json, form, query, or env for the source in use, then zog, then the schema key as written.
  • z.Struct(...).Required() and .Optional() compile and do nothing. An optional nested struct needs z.Ptr(z.Struct(...)).NotNil().
  • Wrap the schema in z.Ptr wherever the destination field is a pointer. A z.Slice(...) against a *[]T field panics with a type-cast error.
  • z.Ptr carries only .NotNil(). Put Required, Default, Catch, Test, and Transform on the inner schema.
  • Declare every schema once, at package level. A schema rebuilt per call costs roughly twice the time and several times the memory of a reused one, and the gap widens with the number of fields.
  • Pick, Omit, Extend, and Merge return shallow copies and are not type-checked. A key naming no struct field panics at execution rather than failing to compile.

Read [${CLAUDE_SKILL_DIR}/references/schema-catalog.md] when reaching for a constructor, a validator, a test option, or an issue code that is not already in the chain — it carries every schema type with its full method set and signatures, the three option families, and the issue-code and type constants.

Read the full file on GitHub · 186 lines

Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 186 lines · 45 tokens per session scan B 715be7da2655

Subscribe to this mod's changes

zog is a skill published in the GitHub repository xobotyi/cc-foundry (20 stars, last pushed 3d ago), licensed MIT. It adds 45 tokens to every session and 3,023 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 1 finding (strips warnings and disclaimers). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

golang-pro

Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with generics, interfaces, and robust error handling. Use when building Go applications requiring concurrent programming…

Jeffallan/claude-skills · 95 tokens

golang-graphql

Implements GraphQL APIs in Golang using gqlgen or graphql-go. Apply when building GraphQL servers, designing schemas, writing resolvers, handling subscriptions, or integrating GraphQL with existing Go HTTP services. Also apply when the codebase imports github.com/99designs/gqlgen or github.com/graph-gophers/graphql-go.

samber/cc-skills-golang · 77 tokens

layered-architecture-types

Enforce primitive-at-edges / strong-types-in-Business layering and the toBus/fromBusResponse/toDB converter pattern. Use when writing, editing, or auditing Go files under app/, business/domain/, or .../stores/db.

ardanlabs/service · 56 tokens

golang-grpc

Provides gRPC usage guidelines, protobuf organization, and production-ready patterns for Golang microservices. Use when implementing, reviewing, or debugging gRPC servers/clients, writing proto files, setting up interceptors, handling gRPC errors with status codes, configuring TLS/mTLS, testing with bufconn, or…

samber/cc-skills-golang · 72 tokens

golang-swagger

Golang OpenAPI/Swagger documentation with swaggo/swag — annotation comments (@Summary, @Param, @Success, @Router, @Security), swag init code generation, framework integrations (gin, echo, fiber, chi, net/http), security definitions (Bearer/JWT, OAuth2, API key), and struct tags (swaggertype, enums, example…

samber/cc-skills-golang · 146 tokens

goframe-v2

GoFrame development skill. TRIGGER when writing/modifying Go files, implementing services, creating APIs, or database operations. DO NOT TRIGGER for frontend/shell scripts.

hashgraph-online/awesome-codex-plugins · 40 tokens