All skills
bitwarden avatar

/requirements-elicitation

@faf72be official
by bitwardenbitwarden/ai-plugins155 stars
20

Extract complete, unambiguous requirements from specifications. Use when analyzing feature requests, processing enhancement specifications, or identifying missing information. Trigger phrases: "extract requirements", "analyze specification", "identify requirements", "clarify ambiguities". After extracting requirements, use the `work-breakdown` skill.

  • 2 files
  • 7.1 KB
  • Updated 7 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/requirements-elicitation

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ95 tokens always: the name and description. β‰ˆ1.2k when used: this file. β‰ˆ488 more on demand in 1 file.

Requirements Elicitation

Key Capabilities

  1. Extract Requirements β€” Identify functional and non-functional requirements from multiple sources
  2. Clarify Ambiguities β€” Flag unclear specifications and formulate targeted questions
  3. Identify Constraints β€” Find technical, business, security, and resource limitations
  4. Categorize Requirements β€” Organize by type (functional, non-functional, security, performance)

Approach

1. Read and Understand

  • Read entire specification thoroughly, including all referenced documents
  • Identify the primary source (main requirement) vs. supporting documentation
  • Note the scope and context of the request

2. Extract Explicit Requirements

  • Capture clearly stated requirements
  • Document exact specifications (API signatures, data formats, performance metrics)
  • Preserve technical details verbatim

3. Identify Implicit Requirements

  • Infer unstated but necessary requirements (e.g., error handling, validation, logging)
  • Consider security implications based on Bitwarden security principles (P01-P06)
  • Identify data classification needs (Vault Data, Protected Data, secure channels)

4. Flag Ambiguities and Gaps

  • Document unclear or missing information
  • Formulate specific questions to resolve ambiguities
  • Identify conflicting requirements between sources
  • Note assumptions being made

5. Document Constraints

  • Technical constraints (APIs, platforms, compatibility)
  • Security constraints (data protection, authentication, authorization)
  • Resource constraints (performance, storage, bandwidth)
  • Business constraints (timeline, scope, dependencies)

6. Create Acceptance Criteria

  • For each requirement, define testable acceptance criteria
  • Specify verification methods (commands, tests, manual checks)
  • Include edge cases and error scenarios

Bitwarden-Specific Considerations

Security Requirements

Always consider and document:

  • Data classification β€” Is this Vault Data, Protected Data, or other?
  • Data states β€” Requirements for data at rest, in use, in transit
  • Security channels β€” Need for secure/trusted channels?
  • Security principles β€” Which principles (P01-P06) apply?
  • Threat scenarios β€” What could go wrong?

Common Bitwarden Requirement Types

  • Authentication/Authorization β€” Who can access what?
  • Encryption β€” What data needs protection and how?
  • Zero-knowledge β€” Server must not have access to plaintext (P01)
  • Cross-platform β€” Works on all Bitwarden clients?
  • Backwards compatibility β€” Maintains existing behavior?

Example

See examples/export-functionality.md for a complete worked example.

Best Practices

Do's

  • βœ… Ask "what" questions, not "how" β€” Focus on requirements, not implementation
  • βœ… Document assumptions explicitly β€” Make implicit knowledge visible
  • βœ… Create testable acceptance criteria β€” Avoid vague success measures
  • βœ… Consider all user types β€” Free users, premium, enterprise, admins
  • βœ… Think about edge cases β€” Empty vaults, huge vaults, network failures
  • βœ… Reference Bitwarden security principles β€” Ground security requirements in P01-P06
  • βœ… Use Bitwarden vocabulary β€” Standard terminology for data, channels, security

Don'ts

  • ❌ Avoid: Making technical implementation decisions β€” That's the architect's job
  • ❌ Avoid: Assuming unstated requirements are obvious β€” Explicit is better
  • ❌ Avoid: Generic acceptance criteria β€” "It works" is not testable
  • ❌ Avoid: Ignoring security implications β€” Security is never optional at Bitwarden
  • ❌ Avoid: Skipping constraints β€” They're as important as requirements

Output Format

Organize extracted requirements in structured sections:

## Functional Requirements

1. REQ-F-001: [Specific capability the system must have]
   - **Acceptance Criteria**: [Testable condition]
   - **Priority**: Critical | High | Medium | Low

## Non-Functional Requirements

- **Performance**: [Response time, throughput, resource usage]
- **Reliability**: [Error handling, edge cases, availability]
- **Compatibility**: [Platform support, backwards compatibility]
- **Usability**: [User experience expectations]

## Security Requirements

- **Data Classification**: [Vault Data | Protected Data | Other]
- **Security Principles**: [P01, P02, P03, P04, P05, P06 as applicable]
- **Threat Considerations**: [What could go wrong?]

## Constraints

- **Technical**: [APIs, platforms, dependencies]
- **Business**: [Timeline, scope, resources]
- **Security**: [Compliance, encryption, authentication]

## Open Questions

1. [Specific question needing stakeholder input]
2. [Ambiguity requiring clarification]
3. [Missing information that blocks complete specification]

## Assumptions

- [Assumption 1: explicit statement of what's assumed]
- [Assumption 2: should be validated with stakeholders]

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at faf72be. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 7 months ago

README badge

README badge for bitwarden/ai-plugins/requirements-elicitation

Extracts functional, non-functional, and security requirements from specifications, flags ambiguities, and documents constraints and acceptance criteria. Designed for Bitwarden projects, with built-in consideration of data classification, security principles (P01-P06), and zero-knowledge architecture constraints.

Generated from the current SKILL.md.

What triggers this skill to run?
Use phrases like 'extract requirements', 'analyze specification', 'identify requirements', or 'clarify ambiguities'. The skill is designed to run on feature requests, enhancement specifications, or documents with missing information.
Does this skill handle security requirements?
Yes. It explicitly identifies data classification (Vault Data, Protected Data), applies Bitwarden security principles (P01-P06), and documents threat scenarios and data states (at rest, in use, in transit).
What comes after using this skill?
After extracting requirements, use the work-breakdown skill to decompose them into actionable tasks.
Does this skill make implementation decisions?
No. It focuses on identifying and clarifying requirements, not on how to build them. Implementation decisions are left to architects and engineers.

Generated from the current SKILL.md. These answers refresh after source changes.