Skip to content
Back to skills

Architecture Review

ASecurity

Reviews a technical proposal before implementation. Use for system architectures, feature specs, RFCs, ADRs, and issues that define how a system change should work. Finds material ambiguity and flaws in correctness, scalability, performance, security, operations, and proof.

  • 412 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 6, 2026
developmentrustgoawssecurityperformance

Security analysis

A100/100

Scanned October 6, 2026

npx -y skills add owainlewis/blueprint --skill architecture-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Architecture Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Architecture Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/owainlewis-architecture-review/badge)](https://www.skillsdirectory.com/skills/owainlewis-architecture-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: architecture-review
description: "Reviews a technical proposal before implementation. Use for system architectures, feature specs, RFCs, ADRs, and issues that define how a system change should work. Finds material ambiguity and flaws in correctness, scalability, performance, security, operations, and proof."
user-invocable: true
argument-hint: "[architecture, spec, RFC, ADR, or issue]"
---

# Architecture review

Find choices that could make a technical proposal wrong, unsafe, or impossible
to prove. Review the proposed behavior and tradeoffs, not the document's size
or format.

Use one fresh subagent that did not write the proposal. Give the reviewer the
complete context. Tell the reviewer to work directly without delegating. If
you are that reviewer, review directly. Stay read-only.

If fresh subagents are unavailable, stop and report that independent review is
blocked. Continue only if the user explicitly accepts a documented self-review.

## Process

1. Read the goal, proposal, requirements, intended architecture, repository instructions, relevant current code,
   tests, schemas, configuration, and linked material. Treat claims about the
   current system as unverified until code, tests, schemas, configuration,
   infrastructure, or relevant runtime evidence supports them.
2. State the problem, affected user, intended outcome, success measure, scope,
   constraints, and main tradeoff. Report any that the proposal leaves unclear.
3. Trace one real case from input to observable outcome. Include ownership,
   validation, state changes, side effects, response timing, failure, retry,
   cleanup, and what the user sees where they matter.
4. Challenge the chosen design with the review focus below. Look for a simpler
   choice that reaches the same outcome and proof with less state, coupling,
   duplication, or operational work.
5. Surface material open questions. Recommend an answer when evidence supports
   one. Do not invent questions that cannot change the design.
6. Return findings, open questions, a short assessment, and one verdict.
   Do not rewrite the proposal, plan the work, review implementation code, or
   implement changes.

## Review focus

- Check fit with requirements and accepted architecture. Verify current-state claims without requiring a new system to have code.
- Check ownership, boundaries, interfaces, data,
  compatibility, migration, rollout, and rollback.
- Trace partial failure, retry, cancellation, concurrency, startup, shutdown,
  and recovery where they affect the proposal.
- Check claimed scale, limited resources, latency, throughput, storage, cost,
  dependency failure, and operator recovery only where they can change the choice.
- Check identity, authorization, untrusted input, credentials, destructive
  authority, and sensitive data handling.
- Require observable acceptance criteria and proof for important rules and
  failure paths. Do not let implementation invent user-visible behavior,
  interfaces, data rules, security policy, or failure behavior.

## Material questions

Report an open question only when two capable implementations could answer it
differently in a way that affects users, data, interfaces, security, scale,
performance, operations, cost, compatibility, or proof.

- **Blocking:** implementation should not start without the answer.
- **Important:** the proposal should record the answer, but the reviewer can
  recommend a safe default from available evidence.

Omit questions that are stylistic, safely local to implementation, outside the
stated scope, or speculative beyond the scale the proposal claims to support.

## Findings

Report only flaws that can change the design or its safety:

- **Blocker:** the choice is unsafe, contradicts the goal or current system, or
  cannot recover from an important failure.
- **Important:** the proposal permits materially different implementations or
  leaves a meaningful risk in behavior, scale, performance, security,
  operations, compatibility, or proof.

For each finding or open question include its location, concrete failure or
ambiguity, impact, evidence, and the smallest correction or recommended answer.
Report unclear wording when it prevents a new teammate from explaining,
evaluating, or implementing the design. Omit other writing preferences.

Use plain words. State the exact condition, failure, and effect. Do not hide an
unknown behind vague language such as `may have issues` or `could be risky`.

## Verdict

- `Approve`: no blocker or important findings or open questions remain.
- `Request changes`: the proposal has a fixable blocker or important finding or
  open question.
- `Blocked`: the review lacks required context, repository evidence, specialist
  coverage, or an independent reviewer.

State what remains unverified. Do not approve because the document is detailed
or because every template section exists.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…