Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when filling knowledge-layer context files — auth-model, tenant-boundaries, data-sensitivity, deployment-order, observability — interactive template walkthrough.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Use this skill when:
agents/settings/contexts/ files are still
template stubs from event4u/agent-config.authz-review, data-flow-mapper, migration-safety,
multi-tenant-boundary-review, secrets-and-config-review) reports "I
cannot proceed — agents/settings/contexts/<file>.md is still a template".Do NOT use when:
agent-docs-writing.context-create.domain-invariants.yml, etc.)
— use /memory-add.| File | What it answers | Who reads it |
|---|---|---|
auth-model.md | Roles, permission model, impersonation, known exceptions | authz-review, judge-security-auditor, threat-modeling |
tenant-boundaries.md | Tenancy type, scope propagation, known cross-tenant paths | multi-tenant-boundary-review, blast-radius-analyzer, judge-security-auditor |
data-sensitivity.md | Field classification, masking rules, log-safe types | data-flow-mapper, logging reviewers |
deployment-order.md | Migration strategy, feature flags, rollback plan | migration-safety, judge-bug-hunter, release reviewers |
observability.md | Error tracking, log channels, metrics, known alerts | deploy reviewers, bug-analyzer, incident mode |
The templates ship in src/agent-src/templates/contexts/ and are
copied into agents/settings/contexts/ by the installer.
List agents/settings/contexts/ — which of the five files exist? Which still contain
the <!-- Template shipped by event4u/agent-config. --> HTML comment?
Ask the user which file to work on. Use numbered options:
> 1. auth-model.md — roles, permissions, impersonation
> 2. tenant-boundaries.md — tenancy type and scope propagation
> 3. data-sensitivity.md — field classification and masking
> 4. deployment-order.md — migrations, flags, rollback
> 5. observability.md — errors, logs, metrics, alerts
If multiple files are stubs, default to the order above — auth-model is
the prerequisite for tenant-boundaries; both feed data-sensitivity.
For the chosen file, pull what the codebase already reveals before asking the user. Record the file:line citations — they become the authoritative source when the user is unsure.
| File | Harvest from |
|---|---|
auth-model.md | Policy classes, Gate definitions, permission seeders, role enums, @can directives, middleware |
tenant-boundaries.md | Base query scopes, connection-switching middleware, tenant-resolution service, global scopes, .env vars like TENANT_* |
data-sensitivity.md | ORM hidden-field config (Eloquent $hidden / $casts, Symfony #[Ignore], Prisma select defaults, SQLAlchemy __init__ filters), Sentry beforeSend, logging redaction helpers, API serialisers / resources, export commands |
deployment-order.md | database/migrations/, feature-flag config (Pennant / LaunchDarkly), deploy scripts, CI workflow, rollback runbooks in docs/ |
observability.md | config/logging.php, Sentry init, dashboard links in READMEs, alert rules in Terraform/Grafana dashboards |
Start the walkthrough by showing the harvested evidence — the user only has to confirm or correct, not invent from scratch.
Open the template and treat every HTML comment as a question for the user. Do NOT fabricate answers to skip a section.
Present each section as:
**Section:** <heading>
**Template asks:** <what the comment says>
**Evidence I found:** <file:line references or "none">
**Proposed content:** <draft or "I need your input">
> 1. Accept the draft
> 2. Edit — tell me what's wrong
> 3. I don't know — mark as "TBD" with a follow-up task
If the user picks "TBD", insert an HTML comment <!-- TBD: <question> -->
at that spot — never a fabricated value. Reviewer skills key on the
comment to warn about incomplete sections.
<!-- Template shipped by ... --> comment only
after at least one section has been authored — an untouched file must
stay recognisable as a stub.## Known exceptions, ## Known alerts, etc.).learning-to-rule-or-skill to expand the template upstream../scripts-run src/scripts/check_portability — project-specific content is
expected here, but the check catches accidental copy of other projects'
identifiers../scripts-run src/scripts/check_references — cross-file links between the
five contexts must resolve.<!-- TBD -->
marker stays.agents/settings/contexts/<file>.md updated with project-specific content; every
section either authored or explicitly marked <!-- TBD: ... -->.TBD, and which downstream reviewer skills are now unblocked.agents/learnings/ for any template gap
the user hit (missing section, ambiguous field) — feeds the curated
self-improvement pipeline via learning-to-rule-or-skill.<!-- TBD: ... --> marker is
always better than a made-up entry — reviewer skills trust this file.data-sensitivity.md is the highest-leverage file and also the one most
likely to be skipped as "boring". Prioritise it after auth-model —
missing entries here become production leaks, not review nits.tenant-boundaries.md SHOULD be deleted, not stubbed — the checklist
explicitly says so at the top of the file.If the context file declares its own load_context: (chain reasoning),
use logical names rooted at the source — contexts/<area>/<file>.md
for package material or agents/settings/contexts/<file>.md for project-local
material. The .agent-src.uncondensed/ prefix is rejected by the
schema regex and by scripts/lint_load_context.ts. Body links to
docs/guidelines/... use the verbatim ../../docs/... relative form.
Canonical reference: rule-writing § 3b and
docs/contracts/load-context-schema.md.
Apply the Frugality Charter to every context file you author.
Examples in this artifact:
Pre-save self-check:
<add me>, TBD) shipped instead of actual
content?まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Use when reviewing UI for accessibility — WCAG 2.2 AA, keyboard nav, focus, ARIA, contrast, screen-reader semantics — even on 'is this a11y-OK?' or 'mach das barrierefrei'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when defining or auditing the activation event — aha-moment selection, retention correlation, falsifiable definition. Triggers on 'what is our aha moment', 'redefine activation'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when capturing an architectural decision — file naming, next ADR number, Status / Context / Decision / Consequences, index regen; fires even without saying 'ADR'.
日本語の概要は準備中です。原文の説明を表示しています。
Adversarial critique — devil's advocate, stress-test, honest teardown ('poke holes', 'be brutal', 'was hältst du davon'); explicit request only. Routine code or design review → code-review.
日本語の概要は準備中です。原文の説明を表示しています。
Use when reading, creating, or updating agent documentation, module docs, roadmaps, or AGENTS.md. Understands the full .augment/, agents/, and copilot-instructions structure.
日本語の概要は準備中です。原文の説明を表示しています。
Use for an adversarial red-team / blue-team / auditor review of an AI agent's CONFIG + behaviour (rules, skills, MCP, hooks, permissions) — attack-chain → defensive-gap list, not a code audit.
日本語の概要は準備中です。原文の説明を表示しています。