Tactical DddSAFE
The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Cursor, Copilot and more with absolute confidence.
Overview
The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Cursor, Copilot and more with absolute confidence.
069343ba7895OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: tactical-ddd description: Detects anemic domain models, validates and refactors them into rich domain models, and enforces tactical DDD patterns (Entities, Value Objects, Aggregates, Domain Services, Domain Events). Use when the user asks to validate, review, or check domain models or DDD code; detect anemia; refactor domain objects; improve encapsulation; or mentions terms like "anemic model", "rich domain", "aggregate", "value object", "domain event", "ubiquitous language", "is this good DDD", "does this follow DDD", or "check my domain". Do NOT use for module or service boundary design, architectural decomposition, strategic DDD context mapping, or code outside the domain layer (DTOs, controllers, infrastructure adapters). --- # Tactical DDD — Rich Domain Modeling ## Workflow Determine the user's intent first: | Intent | Phases to run | |--------|--------------| | "validate / review / check / is this correct?" | Phase 1 + 2 only → report findings, ask before refactoring | | "fix / refactor / improve / clean up" | Phase 1 + 2 + 3 | | "how should I design / model this?" | Load [reference.md](reference.md) directly | ### Phase 1 — Detect Load [detection.md](detection.md) and scan the target code for anemia signals. Produce a severity score and list of affected classes. ### Phase 2 — Assess For each affected class, determine the correct building block: | Has unique identity tracked over time? | Has invariants tying multiple objects? | → Building Block | |----------------------------------------|----------------------------------------|-----------------| | Yes | — | **Entity** | | No | — | **Value Object** | | Yes (root) + children with shared invariants | Yes | **Aggregate** | | Operation spans multiple Aggregates/doesn't belong to any | — | **Domain Service** | Prefer Value Objects over Entities. Prefer small Aggregates over large ones. **If intent was validate/review**: stop here. Report findings using the output format below. Ask "Would you like me to apply these fixes?" before proceeding. ### Phase 3 — Refactor Load [refactoring.md](refactoring.md) for step-by-step moves. Apply in this order: 1. Replace setter chains with a single expressive method 2. Move service logic into the Aggregate that owns it 3. Add business guards at the top of each method 4. Publish a Domain Event after each successful state change 5. Replace primitive types with Value Objects For deep pattern questions (boundary design, event modeling, service vs. entity decision), load [reference.md](reference.md). --- ## Quick Anemia Signals (scan first) ``` public setX() / public setY() → behaviour should be encapsulated service.doX(entity, ...) → logic likely belongs in entity entity.setA(); entity.setB(); ... → setter chain = missing intent method no domain methods beyond getters → pure data bag ``` --- ## Golden Rules 1. **Behaviour with data** — Objects own both state and the operations that change it 2. **Ubiquitous Language** — Method names come from the domain, not CRUD (`commitTo`, not `setStatus`) 3. **Small Aggregates** — Root + Value Objects by default; add child Entities only for true invariants 4. **One transaction = one Aggregate** — Cross-Aggregate rules use eventual consistency via Domain Events 5. **Reference by ID** — Never hold object references to other Aggregates 6. **Value Objects first** — Use Entities only when individual identity is essential 7. **Domain Services sparingly** — Excessive services → anemic model 8. **Protect invariants** — The Aggregate is the last line of defence; never trust the caller --- ## Output Format When reviewing code, report: ``` ## Anemia Diagnosis: <ClassName> Severity: [None | Mild | Moderate | Severe] Issues: - <description of problem> Recommended refactoring: - <specific move from refactoring.md> ``` When refactoring, show a before/after diff for each class touched.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
CLAUDE.md
Gates applied: no_behavioural_pass.
069343ba7895full audit observations/trust-audit/skill/tech-leads-club__tactical-ddd.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 069343ba7895 | SAFE | B | 89 | first audit |
Questions
What does the Tactical Ddd skill do?
The secure, validated skill registry for professional AI coding agents. Extend Antigravity, Claude Code, Cursor, Copilot and more with absolute confidence.
Is Tactical Ddd safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Tactical Ddd access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (069343ba7895), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.