All skills
bitwarden avatar

/architecting-solutions

@ded8d7e official
by bitwardenbitwarden/ai-plugins155 stars
20

Architecting solutions at the team level while staying coherent with Bitwarden's holistic architecture. Covers security mindset, architectural judgment, Bitwarden-specific constraints, and working with the architecture group. Use when designing or planning a solution, reviewing architecture within a team's scope, assessing change impact, evaluating trade-offs in different implementations, or deciding whether a choice needs architecture group input.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/architecting-solutions

This session only. Nothing lands on disk.

evalsREADME.md

≈301 tokens on demand. Your agent reads this file only when SKILL.md points to it.

architecting-solutions evals

Behavior test cases for the architecting-solutions skill, in the skill-creator schema.

behavior-eval.json holds nine cases targeting the Bitwarden-specific parts of the skill.

Each case's expectations are the pass criteria. Denominators differ per case because they count expectations, not runs — every expectation is graded independently for both configurations.

Cases are advice-only — they grade the design the skill produces and run no live edits, commits, or PRs, so re-runs are mutation-safe.

Run with /skill-creator:skill-creator in Benchmark mode (with-skill vs. without-skill) with a config-blind grader. Any change to SKILL.md should be paired with a re-run and a refresh of behavior-baseline.json; the baseline is what future comparisons diff against.

behavior-baseline.json records the pass/fail rate per case, keyed by model + effort. Regression check:

diff <(jq -S . behavior-baseline.json) <(jq -S . result.json)

An empty diff means no regression. When a change is intentional and the new numbers are the new desired state, replace behavior-baseline.json with the new results in the same PR as the skill change.

Source: SKILL.md on GitHub

1 warning14d3 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill is an architectural guidance tool that follows security best practices, including explicit warnings about prompt injection. It has a low-risk surface for indirect prompt injection as it is designed to ingest and summarize external documentation from sources like Jira and Confluence.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: MEDIUM · 1 issue

Signed by skilld at ded8d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
What it can do
Reads files Network
All 5 allowed tools
SkillReadGlobGrepWebFetch(domain:contributing.bitwarden.com)
  • Security
  • architecture
  • bitwarden
  • design-review
  • threat-modeling
  • api-design
  • data-access
  • team-coordination

README badge

README badge for bitwarden/ai-plugins/architecting-solutions

Provides decision-making framework for planning and reviewing solutions within Bitwarden's architecture, covering security-first design, blast-radius assessment, multi-client constraints, and when to escalate to the Architecture group. Use when designing features, evaluating trade-offs, or determining whether a change needs cross-team alignment.

Generated from the current SKILL.md.

When should I involve the Architecture group instead of deciding inside my team?
Involve Architecture if the work defines an API or pattern other teams will adopt, makes structural decisions costly to change later (data model, service boundaries, auth), overlaps with existing initiatives, sets a new precedent, or produces external-facing output like CLIs or SDKs. Otherwise, decide inside the team.
How do I work with an initiative shepherd during implementation?
The shepherd owns the vision, ADR, and cross-team consistency; your team owns story breakdown, sizing, and implementation. Insist on a handoff meeting where the shepherd presents findings, then your team does the breakdown. Flag any drift from the PoC pattern before merging, not after.
What security constraints are specific to Bitwarden's architecture?
Classify all data touch points as encrypted or plaintext, never add sensitive data paths without encryption at rest and in transit, require audit trails for sensitive operations, and fail closed when security checks are ambiguous. Threat model early using the dedicated threat-modeling skill for complex features.
How do I handle backwards compatibility with older clients?
The server must support clients up to 2 major versions behind. API changes must be additive — new fields are optional, responses degrade gracefully, and nothing breaks for outdated clients. Never add required fields to existing endpoints.
What should I check before advocating for a design?
Map the blast radius across clients and services, verify existing patterns in the codebase, ask who else is affected (other teams, self-hosted customers, open-source contributors), and test whether the design would survive a production incident review.

Generated from the current SKILL.md. These answers refresh after source changes.