go-web-service-stigs

Automate DISA STIG compliance alignment for Go web services.

1|Updated Feb 19, 2026
One-click install
npx skills add https://github.com/juburr/mad-skills --skill go-web-service-stigs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: go-web-service-stigs
Source: https://github.com/juburr/mad-skills/tree/main/go-web-service-stigs
Command: npx skills add https://github.com/juburr/mad-skills --skill go-web-service-stigs

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

DISA STIGs map to Go web services in ways that are complex and easy to misinterpret. This skill provides a consolidated, practical blueprint for aligning Go HTTP services with ASD STIG, Web Server SRG, and API SRG controls, streamlining evidence collection and hardening.

Core Features & Use Cases

  • STIG mapping: Central crosswalks across API, Web Server, and ASD controls to determine applicability and responsibility.
  • Evidence templates: Ready-to-use templates and references to generate artifacts for audits and compliance reports.
  • Reference patterns: Detailed implementation patterns and code snippets in references/ to guide engineers during reviews.
  • Use Case: An SRE team uses this skill to prepare a DoD-compliant Go service assessment and produce audit-ready documentation.

Quick Start

Review a running Go HTTP service by applying the STIG guidance and generate a compliance report with evidence templates.

Frequently Asked Questions about go-web-service-stigs

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map DISA STIG controls to a Go web service?

DISA STIG controls map to Go web services through consolidated crosswalks across API, Web Server, and ASD SRG controls. This alignment determines control applicability and responsibility for secure development and operation.

How do I generate compliance evidence for a Go HTTP service audit?

Compliance evidence for a Go HTTP service audit is generated using ready-to-use evidence templates and references. These templates produce consistent artifacts required for policy conformance and compliance reports.

What STIG controls apply to Go gRPC and REST services?

STIG controls apply to Go gRPC and REST services by aligning with ASD STIG, Web Server SRG, and API SRG requirements. Scope includes auditing, TLS configuration, and token management to satisfy comprehensive control mappings.

Can I automate STIG compliance checks for Go web services?

Automating STIG compliance checks for Go web services involves applying detailed implementation patterns and code snippets from references. This guides engineers during reviews to produce audit-ready documentation for DoD-compliant assessments.

Does this STIG guidance cover TLS and token management for Go services?

STIG guidance covers TLS and token management for Go services within its scope. It automates alignment with DISA controls to ensure secure development and operation across REST and gRPC implementations.

What is the best way to prepare a DoD-compliant Go service assessment?

Preparing a DoD-compliant Go service assessment requires applying STIG guidance to review a running Go HTTP service and generating a compliance report with evidence templates. This streamlines evidence collection and hardening.