All skills
simota avatar

/builder

@c805268
by shingo imotasimota/agent-skills85 stars
15

Implementing robust business logic, API integrations, data models, and reproducible AI image-generation code with type safety. Use for production implementation, Gemini image API pipelines, or interactive pair programming.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/builder

This session only. Nothing lands on disk.

referencerecipe-verify-gates.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Recipe VERIFY Gates

Recipe-specific acceptance gates. Each runs in addition to the universal 5-axis Impact Scope Check (callers / tests / types+contracts / configs / docs). Referenced from SKILL.md -> Subcommand Dispatch.

  • fix: Scout handoff or standalone bug fix. Target <50 lines. Always include a regression test skeleton at VERIFY. VERIFY: a regression test reproduces the bug red→green (fails on the pre-fix code, passes after); the fix targets the root cause, not the symptom; diff stays <50 lines (else re-scope).
  • crud: Decide DDD vs CRUD at SURVEY and confirm CRUD. Entity + Repository + simple service layer. VERIFY: the DDD-vs-CRUD decision is recorded and "CRUD" is justified (no hidden invariants — if any surface, escalate to ddd, don't smuggle them into a service); boundary input uses .safeParse(); each CRUD op carries a test.
  • api: Always include error categorization (4xx/429/5xx), retry limits, idempotency keys, and circuit breakers. VERIFY: 4xx not retried / 429 honors Retry-After / 5xx bounded exponential backoff (3–5 attempts); retry count is bounded per request; every non-idempotent mutation carries an idempotency key; circuit breaker scoped per-endpoint; responses parsed with .safeParse().
  • ddd: Design Aggregate / Value Object / Domain Event after confirming the Bounded Context. Focus on PLAN. VERIFY: Bounded Context confirmed before any tactical pattern (never tactical-without-strategic); entities/VOs are valid-at-construction (invariants enforced in constructor/factory, never in callers — no half-built objects); domain events emitted at state transitions; exhaustiveness checks on discriminated unions.
  • harden: Read the Forge L0-L3 level and raise it to production quality (type safety, validation, test skeletons). VERIFY: starting Forge L-level recorded and raised; zero any / as-at-boundary / .parse()-at-HTTP remain; boundary validation added; secrets externalized (env/Vault, never inline); test skeletons generated for Radar.
  • port: Language/framework port. Re-implement all source-language tests in the target language → parallel-run compare against source code as a black box → investigate any diff. Delineate from Shift (Shift handles large-scale migration planning; port handles implementation execution). VERIFY: ALL source-language tests re-implemented in the target; parallel-run black-box diff against source = 0 (every diff investigated and resolved, none waived); equivalence is behavioral, not line-by-line.
  • integrate: External API integration (Stripe / Slack / GitHub etc.). Build in order: sandbox verification → secret handling (env / Vault) → vendor-specific retry / rate limit / idempotency → webhook signature verification. VERIFY: exercised against the vendor sandbox before prod; secrets in env/Vault (never hardcoded); webhook signature verified server-side; duplicate/replayed webhooks are idempotent; vendor-specific retry / rate-limit / idempotency wired per that vendor's quirks.
  • patch: Strict scope (≤30 lines / ≤3 files). Regression tests mandatory. Ensure size XS on handoff to Guardian pr. VERIFY: scope held to ≤30 lines / ≤3 files (exceed → escalate to fix/harden, do not stretch patch); regression test present; a clear one-step rollback exists; Guardian-handoff size is XS.
  • pair: Interactive co-implementation (INTERACTIVE — the dialogue is the deliverable). Builder drives, user navigates; propose → agree → implement → verify one increment at a time. VERIFY: increments proposed one at a time (no batch dump), each with its verification stated before implementation; each increment meets the full Core Contract quality bar (types-first / always-valid domain / boundary .safeParse() / no any / edges) — not throwaway code (that is Forge); each increment's diff shown + its verification run green before advancing; a user confirmation gate per increment (never auto-advance, even under AUTORUN — under AUTORUN seed the plan and return Next: USER); iterate bounded to 2 turns/increment; session bounded by max-increments (default 12) / user-stop / goal-met / diminishing-returns, with remaining increments handed off as a standard build plan; the 5-axis Impact Scope Check runs at close. Full contract → reference/pair-programming.md.
  • image / image-edit / image-prompt: Gemini image-generation implementation. VERIFY: deliver code without executing the paid request; read credentials from GEMINI_API_KEY; use a supported SDK/model/endpoint verified from current primary documentation; parse response parts defensively; emit the final English prompt, seed, parameters, timestamped output path, metadata.json, cost caveat, policy notes, and SynthID disclosure.
  • image-batch / image-style / image-postprocess / image-cinematic: Asset-pipeline implementation. VERIFY: preserve the approved brief and rights constraints; bound concurrency/retries and estimate cost; gate batches over 10; retain seed/style metadata; verify checkpoint/dedup or artifact/cohesion checks appropriate to the active recipe; do not silently switch to an external model pipeline.
  • image-provenance / image-policy: Safety and disclosure implementation. VERIFY: policy checks reject prohibited flows before generation; likeness/minor/brand risks and regional rules are explicit; C2PA/SynthID/EXIF handling is documented where applicable; refusal and takedown paths are auditable; any unresolved safety risk blocks completion.

Source: SKILL.md on GitHub

No alerts13d5 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill provides a comprehensive environment for production-grade software development, API integration, and AI image-generation pipelines. It enforces strict engineering standards, including type safety, boundary validation, and secure secret management. While it recommends several external libraries for CLI development and image processing, all targeted resources are well-known and reputable. No malicious patterns, obfuscation, or unauthorized data access were detected.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

  • Runlayer6mo

    3/8 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at c805268. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/builder