Skip to content
Back to skills

Code Quality Standards

ASecurity

Use when writing or reviewing code, choosing a logging format, or deciding between continuous monitoring and one-time tests in this estate

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 19, 2026
ai-agentsshellbashterraformtestingcode-reviewgitdocumentation

Works with

  • cli

Security analysis

A100/100

Scanned September 23, 2026

npx -y skills add dryvist/claude-code-plugins --skill code-quality-standards --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Quality Standards?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Code Quality Standards
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dryvist-code-quality-standards/badge)](https://www.skillsdirectory.com/skills/dryvist-code-quality-standards)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: code-quality-standards
description: Use when writing or reviewing code, choosing a logging format, or deciding between continuous monitoring and one-time tests in this estate
---

# Code Quality Standards

Generic code-quality and review practice is covered by
`superpowers:receiving-code-review` and the official `code-review:code-review`
and `engineering:code-review` skills. This skill holds only what's specific
to this estate.

## Bash / Shell

- **NEVER use `for` loops** — breaks permission matching in this harness,
  requires interactive prompts. Use parallel tool calls or tool-native batch
  operations instead.
- **NEVER generate scripts** — execute commands directly via tool calls (see
  `native-first`, content-guards).

## Logging Standards

Format: `YYYY-MM-DD HH:mm:ss [LEVEL] {message}`

| Level | Use |
| --- | --- |
| ERROR | System failures, exceptions requiring attention |
| WARN | Unexpected but recoverable conditions |
| INFO | Normal operational messages |
| DEBUG | Detailed diagnostic information |

Include context (operation, user, resource). Never log secrets.

## Testing Philosophy

Prefer **continuous real-time monitoring** over one-time tests.

| Use Continuous Monitoring | Use One-Time Tests |
| --- | --- |
| Services with health endpoints | IaC validation (`terraform validate`) |
| Long-running infrastructure | Linting/formatting (pre-commit) |
| Anything that can fail post-deploy | Unit tests (TDD cycle) |

Monitoring MUST proactively alert. Alerting channels (priority order):
Slack, Splunk alerts, email. Silent dashboards are not monitoring.

## Documentation Format

- Hierarchical numbering (1., 1.1., 1.1.1.) for structured content.
- Keep docs concise — AI-first, humans second.
- All Markdown validated by `markdownlint-cli2` via pre-commit hooks.

## Related Skills

- **pr-standards** (github-workflows) — PR & issue standards, PR guards, issue linking

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…