dev-story-1739a2 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited dev-story-1739a2 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill bridges planning and code. It reads a story file in full, assembles all the context a programmer needs, routes to the correct specialist agent, and drives implementation to completion — including writing the test.
The loop for every story:
/qa-plan sprint ← define test requirements before sprint begins
/story-readiness [path] ← validate before starting
/dev-story [path] ← implement it (this skill)
/code-review [files] ← review it
/story-done [path] ← verify and close itAfter all sprint stories are done: run /team-qa sprint to execute the full QA cycle and get a sign-off verdict before advancing the project stage.
Output: Source code + test file in the project's src/ and tests/ directories.
If a path is provided: read that file directly.
If no argument: check production/session-state/active.md for the active story. If found, confirm: "Continuing work on [story title] — is that correct?" If not found, ask: "Which story are we implementing?" Glob production/epics/**/*.md and list stories with Status: Ready.
Before loading any context, verify required files exist. Extract the ADR path from the story's ADR Governing Implementation field, then check:
| File | Path | If missing |
|---|---|---|
| TR registry | docs/architecture/tr-registry.yaml | STOP — "TR registry not found. Run /create-epics to generate it." |
| Governing ADR | path from story's ADR field | STOP — "ADR file [path] not found. Run /architecture-decision to create it, or correct the filename in the story's ADR field." |
| Control manifest | docs/architecture/control-manifest.md | WARN and continue — "Control manifest not found — layer rules cannot be checked. Run /create-control-manifest." |
If the TR registry or governing ADR is missing, set the story status to BLOCKED in the session state and do not spawn any programmer agent.
Read all of the following simultaneously — these are independent reads. Do not start implementation until all context is loaded:
Extract and hold:
Read docs/architecture/tr-registry.yaml. Look up the story's TR-ID. Read the current requirement text — this is the source of truth for what the GDD requires now. Do not rely on any inline text in the story file (may be stale).
Read docs/architecture/[adr-file].md. Extract:
Read docs/architecture/control-manifest.md. Extract the rules for this story's layer:
Check: does the story's embedded Manifest Version match the current manifest header date? If they differ, use AskUserQuestion before proceeding:
[A] Update story manifest version and implement with current rules (Recommended)[B] Implement with old rules — I accept the risk of non-compliance[C] Stop here — I want to review the manifest diff firstIf [A]: edit the story file's Manifest Version: field to the current manifest date before spawning the programmer. Then read the manifest carefully for new rules. If [B]: read the manifest carefully for new rules anyway, and note the version mismatch in the Phase 6 summary under "Deviations". If [C]: stop. Do not spawn any agent. Let the user review and re-run /dev-story.
After extracting the Dependencies list from the story file, validate each:
production/epics/**/*.md to find each dependency story file.Status: field.Complete or Done:AskUserQuestion:[A] Proceed anyway — I accept the dependency risk[B] Stop — I'll complete the dependency first[C] The dependency is done but status wasn't updated — mark it Complete and continueIf a dependency file cannot be found: warn "Dependency story not found: [path]. Verify the path or create the story file."
Read .claude/docs/technical-preferences.md:
Engine: value — determines which programmer agents to useBased on the story's Layer, Type, and system name, determine which specialist to spawn via Task.
Config/Data stories — skip agent spawning entirely: If the story's Type is Config/Data, no programmer agent or engine specialist is needed. Jump directly to Phase 4 (Config/Data note). The implementation is a data file edit — no routing table evaluation, no engine specialist.
| Story context | Primary agent |
|---|---|
| Foundation layer — any type | engine-programmer |
| Any layer — Type: UI | ui-programmer |
| Any layer — Type: Visual/Feel | gameplay-programmer (implements) |
| Core or Feature — gameplay mechanics | gameplay-programmer |
| Core or Feature — AI behaviour, pathfinding | ai-programmer |
| Core or Feature — networking, replication | network-programmer |
| Config/Data — no code | No agent needed (see Phase 4 Config note) |
Read the Engine Specialists section of .claude/docs/technical-preferences.md to get the configured primary specialist. Spawn them alongside the primary agent when the story involves engine-specific APIs, patterns, or the ADR has HIGH engine risk.
| Engine | Specialist agents available |
|---|---|
| Godot 4 | godot-specialist, godot-gdscript-specialist, godot-shader-specialist |
| Unity | unity-specialist, unity-ui-specialist, unity-shader-specialist |
| Unreal Engine | unreal-specialist, ue-gas-specialist, ue-blueprint-specialist, ue-umg-specialist, ue-replication-specialist |
When engine risk is HIGH (from the ADR or VERSION.md): always spawn the engine specialist, even for non-engine-facing stories. High risk means the ADR records assumptions about post-cutoff engine APIs that need expert verification.
Spawn the chosen programmer agent(s) via Task with the full context package:
Provide the agent with:
The agent should:
src/ following the ADR guidelinesFor Type: Config/Data stories, no programmer agent is required. The implementation is editing a data file. Read the story's acceptance criteria and make the specified changes to the data file directly. Note which values were changed and what they changed from/to.
Spawn gameplay-programmer to implement the code/animation calls. Note that Visual/Feel acceptance criteria cannot be auto-verified — the "does it feel right?" check happens in /story-done via manual confirmation.
For Logic and Integration stories, the test must be written as part of this implementation — not deferred to later.
Remind the programmer agent:
"The test file for this story is required at:[path from Test Evidence section]. The story cannot be closed via/story-donewithout it. Write the test alongside the implementation, not after."
Test requirements (from coding-standards.md):
[system]_[feature]_test.[ext]test_[scenario]_[expected_outcome]For Visual/Feel and UI stories: no automated test. Remind the agent to note in the implementation summary what manual evidence will be needed: "Evidence doc required at production/qa/evidence/[slug]-evidence.md."
For Config/Data stories: no test file. A smoke check will serve as evidence.
After the programmer agent(s) complete, collect:
Present a concise implementation summary:
## Implementation Complete: [Story Title]
**Files changed**:
- `src/[path]` — created / modified ([brief description])
- `tests/[path]` — test file ([N] test functions)
**Acceptance criteria covered**:
- [x] [criterion] — implemented in [file:function]
- [x] [criterion] — covered by test [test_name]
- [ ] [criterion] — DEFERRED: requires playtest (Visual/Feel)
**Deviations from scope**: [None] or [list files touched outside story boundary]
**Engine risks flagged**: [None] or [specialist finding]
**Blockers**: [None] or [describe]
Ready for: `/code-review [file1] [file2]` then `/story-done [story-path]`Silently append to production/session-state/active.md:
## Session Extract — /dev-story [date]
- Story: [story-path] — [story title]
- Files changed: [comma-separated list]
- Test written: [path, or "None — Visual/Feel/Config story"]
- Blockers: [None, or description]
- Next: /code-review [files] then /story-done [story-path]Create active.md if it does not exist. Confirm: "Session state updated."
If any spawned agent (via Task) returns BLOCKED, errors, or cannot complete:
Common blockers:
/architecture-decision first/create-stories(story, TR-ID, ADR, manifest, engine prefs). Incomplete context produces code that drifts from design.
Guidelines. If the guidelines conflict with what seems "better," flag it in the summary rather than silently deviating.
the story requires touching an out-of-scope file, stop and surface it: "Implementing [criterion] requires modifying [file], which is out of scope. Shall I proceed or create a separate story?"
complete without the test file existing
in the summary; they will be manually verified in /story-done
architectural pattern not covered by the ADR, surface it before implementing: "The ADR doesn't specify how to handle [case]. My plan is [X]. Proceed?"
/code-review [file1] [file2] to review the implementation before closing the story/story-done [story-path] to verify acceptance criteria and mark the story complete/team-qa sprint for the full QA cycle before advancing the project stage~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.