Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Code Go Git

ASecurity

Idiomatic review for go-git/go-git v5 concurrent access. Use when reviewing Go code that imports go-git, uses git.Repository, Worktree, CommitIter, or ObjectStorage. Covers the library's documented non-thread-safety, per-repo mutex requirements, and iterator lifetime rules.

8 stars
0 votes
0 copies
0 views
Added 9/20/2026
ai-agentsgogitapi

Works with

cursorapi

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add tstapler/dotfiles --skill code-go-git --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Go Git?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Go Git
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tstapler-code-go-git/badge)](https://www.skillsdirectory.com/skills/tstapler-code-go-git)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: code-go-git
description: Idiomatic review for go-git/go-git v5 concurrent access. Use when reviewing Go code that imports go-git, uses git.Repository, Worktree, CommitIter, or ObjectStorage. Covers the library's documented non-thread-safety, per-repo mutex requirements, and iterator lifetime rules.
---

# code-go-git

Idiomatic review checklist for go-git v5 concurrent access patterns.

## MUST FIX

1. [SAFETY] `*git.Repository` is NOT goroutine-safe — a per-repo `sync.Mutex` (not `sync.RWMutex`) is required for all access. Issue #773 is open as of v5.18.
2. [SAFETY] The packfile `MemoryIndex` has a confirmed concurrent-map crash (`fatal error: concurrent map read and map write`) triggered by concurrent `repo.Log()` / `CommitObject` on the same repo. Issue #1121, June 2024, unfixed in v5.x.
3. [SAFETY] `repo.Log()`, `CommitObject()`, and all iterator types are NOT safe to call concurrently on the same `*git.Repository`.
4. [CONCURRENCY] `repo.Worktree()` / `wt.Status()` wraps the same underlying object storage — calling concurrently on the same repo is unsafe.
5. [CONCURRENCY] The per-repo mutex must cover the **full iterator lifetime**, not just the initial API call. Iterators lazily read from shared object storage on each `Next()` — releasing the lock between obtaining an iterator and exhausting it is a data race.
6. [CONCURRENCY] `sync.RWMutex` does NOT help — go-git "read" operations mutate internal maps (object cache, MemoryIndex). Use `sync.Mutex` only.
7. [SAFETY] v5.17.0 added extension validation: `git.PlainOpen` now returns errors for repos with unsupported extensions. Errors from `PlainOpen` must propagate; never store a nil repo.
8. [ANTI-PATTERN] Never cache a `CommitIter` or `ObjectIter` across calls — iterators hold internal cursor state over shared storage. Create and fully drain within one mutex-protected window.
9. [ANTI-PATTERN] Never cache a `*Worktree` in a long-lived struct — it holds a snapshot of the HEAD/filesystem state and becomes stale after `git fetch` or index changes.
10. [ANTI-PATTERN] Never call `git.PlainOpen` while holding the per-repo mutex — `PlainOpen` reads `.git/config`, `HEAD`, and packed-refs from disk (I/O-bound). Open outside the lock, then store via `sync.Map.LoadOrStore`.
11. [CONCURRENCY] Concurrency fixes for `CommitObjects().Foreach()` and related iterators are v6-exp only and NOT backported to v5. There is no "safe subset" of go-git v5 that is natively goroutine-safe for shared-repo reads.

## SUGGEST

12. [PERF] `wt.Status()` is pathologically slow on repos with large numbers of untracked files — it hashes every untracked file regardless of `.gitignore`. Issue #181, open since 2020. Consider a TTL cache on the status result or a `git status --porcelain` subprocess fallback for large repos.
13. [CONCURRENCY] `sync.Map.LoadOrStore` is correct for cache-level concurrency. A `singleflight.Group` per path would also prevent duplicate `PlainOpen` calls under contention — evaluate if `PlainOpen` latency is a measured bottleneck.

## STYLE

14. [STYLE] `sync.Map` at the cache level (one entry per repo path) is the correct granularity. Per-repo `sync.Mutex` on the `*cachedRepo` entry is the correct serialisation granularity. Do not conflate the two.
15. [STYLE] `map[plumbing.Hash]struct{}` is idiomatic for sets. `map[plumbing.Hash]bool` works but communicates less intent.

## References
- [Concurrency Issues #773](https://github.com/go-git/go-git/issues/773)
- [MemoryIndex crash #1121](https://github.com/go-git/go-git/issues/1121)
- [Status() slow with untracked files #181](https://github.com/go-git/go-git/issues/181)

Attribution

tstaplertstapler
View sourceMore from tstapler →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Caveman

Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.

1023331 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

686011 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3331 votes

catchup

Recovers prior coding-agent session context by running `catchup <agent> --since-compact`, which extracts a clean summary of a previous Codex, Claude Code, Antigravity, OpenCode, or Pi Agent session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", or asks to recover/summarize a previous session before continuing. Do NOT use for the current conversation, git history, or any non-agent log.

611 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →