Skip to content
Back to skills

Validation Gates

ASecurity

Defines the ten gates delegated work passes, from secret scanning and lint/test/build to blast radius, dependency audit, browser, regression and smoke tests. Use when deciding which checks a change needs, or whether work is ready to merge or deploy.

  • 80 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 28, 2026
ai-agentsnodeawstestinggitapidatabasefrontendsecuritydocumentation

Works with

  • terminal
  • api
  • mcp

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add monkilabs/opencastle --skill validation-gates --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Validation Gates?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Validation Gates
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/monkilabs-validation-gates/badge)](https://www.skillsdirectory.com/skills/monkilabs-validation-gates)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: validation-gates
description: "Defines the ten gates delegated work passes, from secret scanning and lint/test/build to blast radius, dependency audit, browser, regression and smoke tests. Use when deciding which checks a change needs, or whether work is ready to merge or deploy."
---

# Validation Gates

The project's commands live under Key Commands in `.opencastle/project.instructions.md`; with a task runner (Nx, Turborepo), its skill has them. Every gate below runs those, never a guessed `npm run …`.

| Gate | Name | Runs When |
|------|------|-----------|
| 1 | Secret Scanning | Every delegation |
| 2 | Deterministic Checks | Every delegation |
| 3 | Blast Radius Check | Every delegation |
| 4 | Dependency Audit | When `package.json` or lockfiles change |
| 5 | Fast Review | Every delegation (with auto-PASS exceptions) |
| 6 | Cache Clearing | Only when a stale cache is suspected |
| 7 | Browser Testing | UI changes |
| 8 | Regression Testing | Every delegation |
| 9 | Panel Review | High-stakes changes only |
| 10 | Final Smoke Test | Feature completion (after all tasks Done) |

## Gate 1: Secret Scanning

**Secret scan (Constitution rule 1).** Block on any token, key, password, or
connection string in code, logs, commits, or terminal output.

Scan for: AWS keys (`AKIA...`), API tokens (`sk-...`, `ghp_...`), private keys,
database URIs, hardcoded `password`/`secret`/`api_key`/`token` assignments
(assignments, not references), `.env` contents pasted into source, and
base64-encoded secrets.

On a hit: block, name the file and line, and re-delegate with an instruction to use
an environment variable. Already committed? Rotate it - git history is permanent.

Not a hit: obviously fake test fixtures (`sk-test-1234567890`), documentation
placeholders (`YOUR_API_KEY_HERE`), and pattern matches inside explanatory
comments.

Scan every diff **before** any other gate: `gitleaks git --redact --log-opts="main..HEAD"` for the branch's commits, `gitleaks dir <path>` for uncommitted files (or the CI equivalent). Fail on any finding.

## Gate 2: Deterministic Checks

Run the project's own lint (with auto-fix), test and build commands for every affected project. All must pass with zero errors.

## Gate 3: Blast Radius Check

| Metric | Normal | Warning | Escalate |
|--------|--------|---------|----------|
| Lines changed | ≤200 | 201–500 | >500 |
| Files changed | ≤5 | 6–10 | >10 |
| Projects affected | ≤1 | 2 | >2 |

- **Normal** — proceed
- **Warning** — log; investigate partition drift
- **Escalate** — STOP; verify partition; split or revert; no auto-PASS

**Sensitive files** (always Warning): `**/auth/**`, DB migrations, `next.config.*`, `.env*`, `.github/workflows/**`, lockfiles — also triggers Gate 4.

## Gate 4: Dependency Audit

> Runs only when `package.json`, `yarn.lock`, `package-lock.json`, `pnpm-lock.yaml`, or similar lockfiles are modified.

- **Vulnerability:** `npm audit --audit-level=high` — no new high/critical, else BLOCK (patched version or alternative).
- **Bundle size:** frontend pkgs ≤50KB gzipped (project policy) — SHOULD-FIX; blocking if >200KB.

Full checklist (license, duplicates, maintenance, peer deps, type coverage) with commands: [REFERENCE.md](REFERENCE.md).

## Gate 5: Fast Review

Spawn a reviewer sub-agent (load **fast-review**). Auto-PASS rules, retries and escalation: the **fast-review** Handle Verdict table.

## Gate 6: Cache Clearing

Skip unless a stale cache is the suspect: the browser shows old output, or a build reports files that no longer exist. Then clear the framework cache (e.g. `.next/cache`, `node_modules/.cache`) and the project's own build output directory, named in its build config, and rebuild.

## Gate 7: Browser Testing

UI changes are verified in Chrome with the **browser-testing** skill (Chrome DevTools MCP: `navigate_page`, `take_snapshot`, `evaluate_script` with a `function`). Start the dev server → verify ACs → every project breakpoint → at most 3 screenshots, as evidence.

## Gate 8: Regression Testing

1. Full test suite for all affected projects.
2. Browser-test adjacent pages (navigation, routing, back-button) — find them via `rg "href=\"/changed-path|import .*from '@/components/changed'"`.
3. Find consuming apps/packages via `rg "from '@/components/PriceRange'|@my-org/ui-package"`; run their tests or smoke builds.

## Gate 9: Panel Review

Load **panel-majority-vote** — 3 isolated reviewers, majority (2/3) wins. Use for: the 3rd fast-review FAIL, security-sensitive changes, DB migrations.

## Gate 10: Final Smoke Test

> Runs once after ALL tasks are Done.

The project's full build and test commands, its E2E suite included, from a clean state → E2E browser walkthrough → cross-task integration check → responsive sweep (if UI). On failure: re-delegate specific failing integration only.

Files in this skill

  • REFERENCE.md1.7 KB
  • SKILL.md4.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…