agentic-development-principles — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited agentic-development-principles (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
"AI is the copilot; you are the pilot" AI agents amplify the developer's thinking and take over repetitive work, but final decision-making authority and responsibility always remain with the developer.
AI performs much better with small, clear instructions than with large, ambiguous tasks.
| Wrong example | Right example |
|---|---|
| "Build me a login page" | 1. "Create the login form UI component" |
| 2. "Implement the login API endpoint" | |
| 3. "Wire up the authentication logic" | |
| 4. "Write test code" | |
| "Optimize the app" | 1. "Analyze performance bottlenecks" |
| 2. "Optimize database queries" | |
| 3. "Reduce frontend bundle size" |
Step 1: Design and validate the model/schema
Step 2: Implement core logic (minimum viable functionality)
Step 3: Connect APIs/interfaces
Step 4: Write and run tests
Step 5: Integrate and refactorContext (the AI's working memory) should always be kept fresh and compact.
#### Strategy 1: Single-purpose conversation
Session 1: Work on the authentication system
Session 2: Work on UI components
Session 3: Write test code
Session 4: DevOps/deployment work#### Strategy 2: HANDOFF.md technique When the conversation gets long, summarize only the essentials and hand them to a new session:
# HANDOFF.md
## Completed work
- ✅ Implemented user authentication API
- ✅ Implemented JWT token issuance logic
## Current status
- Working on token refresh logic
## Next tasks
- Implement refresh tokens
- Add logout endpoint
## Tried but failed
- Failed to integrate Redis session store (network issue)
## Cautions
- Watch for conflicts with existing session management code#### Strategy 3: Monitor context state
#### Strategy 4: Optimization metrics
| Metric | Recommended value | Action |
|---|---|---|
| Conversation length | Keep to a reasonable level | Create HANDOFF.md if it gets long |
| Topic count | 1 (single purpose) | Use a new session for new topics |
| Active files | Only what's needed | Remove unnecessary context |
Choose an appropriate abstraction level depending on the situation.
| Mode | Description | When to use |
|---|---|---|
| Vibe Coding | High level (see only overall structure) | Rapid prototyping, idea validation, one-off projects |
| Deep Dive | Low level (go line-by-line) | Bug fixes, security review, performance optimization, production code |
When adding a new feature:
1. High abstraction: "Create a user profile page" → understand overall structure
2. Medium abstraction: "Show the validation logic for the profile edit form" → review a specific feature
3. Low abstraction: "Explain why this regex fails email validation" → detailed debuggingIf you've repeated the same task 3+ times → find a way to automate it
And the automation process itself → automate that too| Level | Approach | Example |
|---|---|---|
| 1 | Manual copy/paste | AI output → copy into terminal |
| 2 | Terminal integration | Use AI tools directly |
| 3 | Voice input | Voice transcription system |
| 4 | Automate repeated instructions | Use project config files |
| 5 | Workflow automation | Custom commands/scripts |
| 6 | Automate decisions | Use Skills |
| 7 | Enforce rules automatically | Use hooks/guardrails |
Analyze without executing; execute only after review/approval
When to use:
AI directly edits code and runs commands
When to use:
"Write tests for this function. Include edge cases too." "Create a draft PR for these changes" "Review the code you just generated again.
Validate every claim, and summarize the verification results in a table at the end."| Principle | Core | Practice |
|---|---|---|
| 1. Divide and conquer | Small, clear units | Split into independently verifiable steps |
| 2. Context management | Keep it fresh | Single-purpose conversations, HANDOFF.md |
| 3. Abstraction choice | Depth per situation | Adjust Vibe ↔ Deep Dive |
| 4. Automation² | Remove repetition | Automate after 3 repetitions |
| 5. Plan/execute balance | Caution first | Plan 70-90%, execute 10-30% |
| 6. Verification/reflection | Check outputs | Tests, reviews, self-verification |
"To truly master AI tools, you need to use them enough"
Learning by using is key - theory alone is not enough; you need to experience different situations in real projects.
When instructing an AI:
1. Clearly (Specific)
2. Step-by-step (Step-by-step)
3. Verifiable (Verifiable)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.