skills/product/acceptance-criteria/SKILL.md
Define testable acceptance criteria from requirements and design. Bridge product requirements with QE test scenarios. Use when: "define acceptance criteria", "how do we know it's done", "what should QE test", "definition of done"
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-product-acceptance-criteriaInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Transform requirements into testable acceptance criteria.
Acceptance criteria are the contract between product and delivery:
Given [precondition/context]
When [action/event]
Then [expected outcome]
Why this format?
Understand:
For each requirement, consider:
Format each scenario:
Given [specific context]
When [specific action]
Then [specific, measurable outcome]
Check each criterion:
### US1: User Authentication
**Happy Path (P0)**:
AC1: Given valid credentials, When user submits login, Then user redirected to dashboard
AC2: Given successful login, When checking session, Then session valid for 30 minutes
**Error Handling (P0)**:
AC3: Given invalid password, When user submits login, Then error message "Invalid credentials"
AC4: Given account locked, When user submits login, Then error message "Account locked"
AC5: Given 3 failed attempts, When user tries again, Then account locked for 15 minutes
**Edge Cases (P1)**:
AC6: Given empty email field, When user submits, Then error "Email required"
AC7: Given malformed email, When user submits, Then error "Invalid email format"
AC8: Given concurrent logins, When second login occurs, Then first session invalidated
**Non-Functional (P1)**:
AC9: Given 1000 concurrent logins, When system under load, Then response time < 2 seconds
AC10: Given login attempt, When credentials checked, Then password encrypted in transit
Data Creation:
Given user on create form
When user enters valid data and submits
Then new record saved and confirmation shown
Data Validation:
Given user on form with required fields
When user submits without filling required field
Then error message shown and form not submitted
Authorization:
Given user without admin role
When user attempts admin action
Then access denied message shown
API Response:
Given valid API request
When endpoint called
Then 200 status and expected JSON schema returned
Acceptance criteria feed directly into test scenarios:
# Product defines AC
/wicked-garden:product:acceptance phases/design/
# Generate test scenarios from AC
/wicked-testing:plan
Flow:
Good acceptance criteria:
## Acceptance Criteria
### User Story: {Story Title}
**Happy Path**:
- AC1: Given {context}, When {action}, Then {outcome} [P0]
**Error Conditions**:
- AC2: Given {error}, When {action}, Then {handling} [P0]
**Edge Cases**:
- AC3: Given {edge}, When {action}, Then {behavior} [P1]
**Non-Functional**:
- AC4: Given {load}, When {action}, Then {performance} [P1]
**Test Data Requirements**:
- {Data needed for testing}
**QE Handoff Notes**:
- {Special testing considerations}
development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).