agentic-development-principles/SKILL.md
Universal principles for agentic development when collaborating with AI agents. Defines divide-and-conquer, context management, abstraction level selection, and an automation philosophy. Applicable to all AI coding tools.
npx skillsauth add autohandai/community-skills agentic-development-principlesInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
"AI is the copilot; you are the pilot" AI agents amplify the developer's thinking and take over repetitive work, but final decision-making authority and responsibility always remain with the developer.
AI performs much better with small, clear instructions than with large, ambiguous tasks.
| Wrong example | Right example | |----------|----------| | "Build me a login page" | 1. "Create the login form UI component" | | | 2. "Implement the login API endpoint" | | | 3. "Wire up the authentication logic" | | | 4. "Write test code" | | "Optimize the app" | 1. "Analyze performance bottlenecks" | | | 2. "Optimize database queries" | | | 3. "Reduce frontend bundle size" |
Step 1: Design and validate the model/schema
Step 2: Implement core logic (minimum viable functionality)
Step 3: Connect APIs/interfaces
Step 4: Write and run tests
Step 5: Integrate and refactor
Context (the AI's working memory) should always be kept fresh and compact.
Session 1: Work on the authentication system
Session 2: Work on UI components
Session 3: Write test code
Session 4: DevOps/deployment work
When the conversation gets long, summarize only the essentials and hand them to a new session:
# HANDOFF.md
## Completed work
- ✅ Implemented user authentication API
- ✅ Implemented JWT token issuance logic
## Current status
- Working on token refresh logic
## Next tasks
- Implement refresh tokens
- Add logout endpoint
## Tried but failed
- Failed to integrate Redis session store (network issue)
## Cautions
- Watch for conflicts with existing session management code
| Metric | Recommended value | Action | |------|---------|------| | Conversation length | Keep to a reasonable level | Create HANDOFF.md if it gets long | | Topic count | 1 (single purpose) | Use a new session for new topics | | Active files | Only what's needed | Remove unnecessary context |
Choose an appropriate abstraction level depending on the situation.
| Mode | Description | When to use | |------|------|----------| | Vibe Coding | High level (see only overall structure) | Rapid prototyping, idea validation, one-off projects | | Deep Dive | Low level (go line-by-line) | Bug fixes, security review, performance optimization, production code |
When adding a new feature:
1. High abstraction: "Create a user profile page" → understand overall structure
2. Medium abstraction: "Show the validation logic for the profile edit form" → review a specific feature
3. Low abstraction: "Explain why this regex fails email validation" → detailed debugging
If you've repeated the same task 3+ times → find a way to automate it
And the automation process itself → automate that too
| Level | Approach | Example | |-------|------|------| | 1 | Manual copy/paste | AI output → copy into terminal | | 2 | Terminal integration | Use AI tools directly | | 3 | Voice input | Voice transcription system | | 4 | Automate repeated instructions | Use project config files | | 5 | Workflow automation | Custom commands/scripts | | 6 | Automate decisions | Use Skills | | 7 | Enforce rules automatically | Use hooks/guardrails |
Analyze without executing; execute only after review/approval
When to use:
AI directly edits code and runs commands
When to use:
Write test code
"Write tests for this function. Include edge cases too."
Visual review
Draft PR / code review
"Create a draft PR for these changes"
Ask for self-verification
"Review the code you just generated again.
Validate every claim, and summarize the verification results in a table at the end."
| Principle | Core | Practice | |------|------|------| | 1. Divide and conquer | Small, clear units | Split into independently verifiable steps | | 2. Context management | Keep it fresh | Single-purpose conversations, HANDOFF.md | | 3. Abstraction choice | Depth per situation | Adjust Vibe ↔ Deep Dive | | 4. Automation² | Remove repetition | Automate after 3 repetitions | | 5. Plan/execute balance | Caution first | Plan 70-90%, execute 10-30% | | 6. Verification/reflection | Check outputs | Tests, reviews, self-verification |
"To truly master AI tools, you need to use them enough"
Learning by using is key - theory alone is not enough; you need to experience different situations in real projects.
When instructing an AI:
1. Clearly (Specific)
2. Step-by-step (Step-by-step)
3. Verifiable (Verifiable)
development
MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat
tools
Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance.
development
Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
development
Search and navigate large codebases efficiently. Use when finding specific code patterns, tracing function calls, understanding code structure, or locating bugs. Handles semantic search, grep patterns, AST analysis.