Recipe VERIFY Gates
Recipe-specific acceptance gates. Each runs in addition to the universal 5-axis Impact
Scope Check (callers / tests / types+contracts / configs / docs). Referenced from
SKILL.md -> Subcommand Dispatch.
fix: Scout handoff or standalone bug fix. Target <50 lines. Always include a regression test skeleton at VERIFY. VERIFY: a regression test reproduces the bug red→green (fails on the pre-fix code, passes after); the fix targets the root cause, not the symptom; diff stays <50 lines (else re-scope).crud: Decide DDD vs CRUD at SURVEY and confirm CRUD. Entity + Repository + simple service layer. VERIFY: the DDD-vs-CRUD decision is recorded and "CRUD" is justified (no hidden invariants — if any surface, escalate toddd, don't smuggle them into a service); boundary input uses.safeParse(); each CRUD op carries a test.api: Always include error categorization (4xx/429/5xx), retry limits, idempotency keys, and circuit breakers. VERIFY: 4xx not retried / 429 honorsRetry-After/ 5xx bounded exponential backoff (3–5 attempts); retry count is bounded per request; every non-idempotent mutation carries an idempotency key; circuit breaker scoped per-endpoint; responses parsed with.safeParse().ddd: Design Aggregate / Value Object / Domain Event after confirming the Bounded Context. Focus on PLAN. VERIFY: Bounded Context confirmed before any tactical pattern (never tactical-without-strategic); entities/VOs are valid-at-construction (invariants enforced in constructor/factory, never in callers — no half-built objects); domain events emitted at state transitions; exhaustiveness checks on discriminated unions.harden: Read the Forge L0-L3 level and raise it to production quality (type safety, validation, test skeletons). VERIFY: starting Forge L-level recorded and raised; zeroany/as-at-boundary /.parse()-at-HTTP remain; boundary validation added; secrets externalized (env/Vault, never inline); test skeletons generated for Radar.port: Language/framework port. Re-implement all source-language tests in the target language → parallel-run compare against source code as a black box → investigate any diff. Delineate from Shift (Shift handles large-scale migration planning; port handles implementation execution). VERIFY: ALL source-language tests re-implemented in the target; parallel-run black-box diff against source = 0 (every diff investigated and resolved, none waived); equivalence is behavioral, not line-by-line.integrate: External API integration (Stripe / Slack / GitHub etc.). Build in order: sandbox verification → secret handling (env / Vault) → vendor-specific retry / rate limit / idempotency → webhook signature verification. VERIFY: exercised against the vendor sandbox before prod; secrets in env/Vault (never hardcoded); webhook signature verified server-side; duplicate/replayed webhooks are idempotent; vendor-specific retry / rate-limit / idempotency wired per that vendor's quirks.patch: Strict scope (≤30 lines / ≤3 files). Regression tests mandatory. Ensure size XS on handoff to Guardianpr. VERIFY: scope held to ≤30 lines / ≤3 files (exceed → escalate tofix/harden, do not stretchpatch); regression test present; a clear one-step rollback exists; Guardian-handoff size is XS.pair: Interactive co-implementation (INTERACTIVE — the dialogue is the deliverable). Builder drives, user navigates; propose → agree → implement → verify one increment at a time. VERIFY: increments proposed one at a time (no batch dump), each with its verification stated before implementation; each increment meets the full Core Contract quality bar (types-first / always-valid domain / boundary.safeParse()/ noany/ edges) — not throwaway code (that is Forge); each increment's diff shown + its verification run green before advancing; a user confirmation gate per increment (never auto-advance, even under AUTORUN — under AUTORUN seed the plan and returnNext: USER); iterate bounded to 2 turns/increment; session bounded by max-increments (default 12) / user-stop / goal-met / diminishing-returns, with remaining increments handed off as a standard build plan; the 5-axis Impact Scope Check runs at close. Full contract →reference/pair-programming.md.image/image-edit/image-prompt: Gemini image-generation implementation. VERIFY: deliver code without executing the paid request; read credentials fromGEMINI_API_KEY; use a supported SDK/model/endpoint verified from current primary documentation; parse response parts defensively; emit the final English prompt, seed, parameters, timestamped output path,metadata.json, cost caveat, policy notes, and SynthID disclosure.image-batch/image-style/image-postprocess/image-cinematic: Asset-pipeline implementation. VERIFY: preserve the approved brief and rights constraints; bound concurrency/retries and estimate cost; gate batches over 10; retain seed/style metadata; verify checkpoint/dedup or artifact/cohesion checks appropriate to the active recipe; do not silently switch to an external model pipeline.image-provenance/image-policy: Safety and disclosure implementation. VERIFY: policy checks reject prohibited flows before generation; likeness/minor/brand risks and regional rules are explicit; C2PA/SynthID/EXIF handling is documented where applicable; refusal and takedown paths are auditable; any unresolved safety risk blocks completion.