Install
$ agentstack add skill-pax-k-build-right-build-right-engineering-principles ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Build Right Engineering Principles
Use this skill as a cross-cutting engineering standard for Build Right projects. It is not a lifecycle phase. It is a review and design lens that other Build Right skills may load when architecture, contracts, implementation boundaries, or engineering-quality tradeoffs matter.
Required Reading
- Read
references/principles.mdbefore making or reviewing changes that touch
architecture boundaries, public contracts, provider adapters, generated code, package ownership, side effects, errors, observability, security, testing strategy, or enforceable policy.
- Do not load the reference for routine product capture, backlog grooming, or
narrow content-only updates unless those topics raise engineering-risk questions.
Operating Mode
- Identify the changed or proposed engineering surface:
architecture, module responsibility, dependency direction, contract, adapter, state shape, side effect, failure path, test, evidence, or policy.
- Apply the review checklist from
references/principles.md. - Separate guidance from enforceable authority. Markdown principles are
guidance until backed by code, checks, tests, schemas, policy, or evidence.
- Prefer the smallest correction that preserves local patterns and reduces
real risk. Do not introduce abstraction only because a principle names one.
- When repeated findings expose a process gap, recommend an enforcement
surface instead of adding more prose.
- Record significant architecture or public-contract choices in the target
repo's normal decision surface.
Closeout
End with the engineering result that matters:
Principles applied:
Required changes:
Enforcement gap:
Residual risk:
User-Visible Status Badge
End every final response with exactly one status badge block:
✅ [DONE] Status: DONE
Decision:
Next action:
Needs user input:
Blocked by:
Use this status map:
✅ [DONE] Status: DONEwhen there are no required changes and
no enforcement gap.
🟢 [GREEN] Status: ALL GREENwhen the reviewed direction is safe to
continue but implementation is not complete.
🟡 [YELLOW] Status: NEEDS INPUTwhen a user or owner architecture,
contract, security, or policy decision is needed.
🟠 [ORANGE] Status: NEEDS WORKwhen AI-owned corrections, tests,
docs, or enforcement work remain.
🔵 [BLUE] Status: WAITING EXTERNALfor external proof, credentials,
production access, publishing, indexing, or third-party state.
🔴 [RED] Status: BLOCKEDfor unresolved conflicts, failed
validation, source mismatch, invalid state, or enforcement blockers.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: pax-k
- Source: pax-k/build-right
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.