Defines 10 sequential validation gates: secret scanning, lint/test/build checks, blast radius analysis, dependency auditing, browser testing, cache management, regression checks, smoke tests. Use when running pre-deploy validation or CI checks, CI/CD pipelines, deployment pipeline validation, pre-merge checks, continuous integration, or pull request validation.
75
94%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
| Gate | Name | Runs When |
|---|---|---|
| 1 | Secret Scanning | Every delegation |
| 2 | Deterministic Checks | Every delegation |
| 3 | Blast Radius Check | Every delegation |
| 4 | Dependency Audit | When package.json or lockfiles change |
| 5 | Fast Review | Every delegation (with auto-PASS exceptions) |
| 6 | Cache Clearing | Before browser testing |
| 7 | Browser Testing | UI changes |
| 8 | Regression Testing | Every delegation |
| 9 | Panel Review | High-stakes changes only |
| 10 | Final Smoke Test | Feature completion (after all tasks Done) |
Secret scan (Constitution rule 1). Block on any token, key, password, or connection string in code, logs, commits, or terminal output.
Scan for: AWS keys (AKIA...), API tokens (sk-..., ghp_...), private keys,
database URIs, hardcoded password/secret/api_key/token assignments
(assignments, not references), .env contents pasted into source, and
base64-encoded secrets.
On a hit: block, name the file and line, and re-delegate with an instruction to use an environment variable. Already committed? Rotate it - git history is permanent.
Not a hit: obviously fake test fixtures (sk-test-1234567890), documentation
placeholders (YOUR_API_KEY_HERE), and pattern matches inside explanatory
comments.
Scan every diff before any other gate: gitleaks detect --source . --verbosity warn (or CI equivalent) — fail on any findings.
Run for every affected project (resolve exact commands via codebase-tool skill): lint (with auto-fix), test, build. All must pass with zero errors.
npm run lint && npm test --silent && npm run build| Metric | Normal | Warning | Escalate |
|---|---|---|---|
| Lines changed | ≤200 | 201–500 | >500 |
| Files changed | ≤5 | 6–10 | >10 |
| Projects affected | ≤1 | 2 | >2 |
Sensitive files (always Warning): **/auth/**, DB migrations, next.config.*, .env*, .github/workflows/**, lockfiles — also triggers Gate 4.
Runs only when
package.json,yarn.lock,package-lock.json,pnpm-lock.yaml, or similar lockfiles are modified.
npm audit --audit-level=moderate — no new high/critical, else BLOCK (patched version or alternative).Full checklist (license, duplicates, maintenance, peer deps, type coverage) with commands: REFERENCE.md.
Spawn reviewer sub-agent (load fast-review skill). PASS → proceed; FAIL → re-delegate (max 2); 3× FAIL → Gate 9. Auto-PASS rules: see fast-review skill.
rm -rf node_modules/.cache .next/cache .astro/ dist/UI changes require Chrome screenshots. Start dev server → verify ACs → responsive breakpoints → capture screenshots. Load browser-testing skill.
{ "tool": "browser-testing/capture_screenshot", "url": "http://localhost:3000", "viewports": ["mobile", "desktop"] }Additional options: see REFERENCE.md.
npm test -- --runInBand for all affected projectsrg "href=\"/changed-path|import .*from '@/components/changed'".rg "from '@/components/PriceRange'|@my-org/ui-package"; run their tests or smoke builds.Load panel-majority-vote skill — spawns 3 isolated reviewers, majority (2/3) wins. Use for: security-sensitive changes, DB migrations, architecture decisions.
Runs once after ALL tasks are Done.
npm run build && npm test && npx playwright testFull build + test from clean state → E2E browser walkthrough → cross-task integration check → responsive sweep (if UI). On failure: re-delegate specific failing integration only.
fa0c341
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.