skills/domain-extractor/SKILL.md
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-domain-extractorInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You extract testable business rules from a codebase — what the business
requires, not how the code does it — and annotate them into the estate store,
so wicked-core builds the [email protected] requirements graph (coverage-gated
fail-closed). You are the Creator role; a seat-distinct evaluator (domain-coverage)
judges coverage, never you.
A single agent (max-turns 12) cannot iterate thousands of nodes. Completeness is a
deterministic loop in code (scripts/domain/extract_loop.py); you are its
driver, not the loop. Your whole job:
Bash call):
python3 scripts/domain/extract_loop.py --db "<estate-store>" --time-budget 780
It seeds its worklist from wicked-core coverage's own unaccounted_nodes — the
SAME authority the coverage gate re-derives against, so there is no denominator
drift — loops every behavior-bearing node, calls the bounded per-node model
for the one thing code can't do (stating the rule), validates each returned
rule, and writes annotate + semantics. Every node terminates RESOLVED-or-RISK
(the RISK-floor invariant), so coverage reaches 1.0 deterministically; the model
only upgrades RISK→RESOLVED quality.coverage=… unaccounted=… processed=…). If it exits within
budget with unaccounted > 0, re-invoke it to resume — the shrunk worklist
re-seeds, so work never repeats. Stop when unaccounted hits 0 or stops shrinking.Extraction is split exactly like the vault:
domain-coverage phase (wicked-core coverage) — never trusted.confidence ∈ [0,1] (ISS-11
hard-fail), grounded provenance{source,ref,source_kinds} — before it counts, or
it is RISK-flagged. Model-driven where judgment is needed; deterministic everywhere.WICKED_ESTATE_BIN / WICKED_CORE_BIN — the peer binaries (resolved by _clients).WICKED_RULE_MODEL_BIN — the bounded per-node rule model (default claude -p).
Set-but-empty is the kill-switch → the harness's --dry-run deterministic stub only.business_rules with minItems 1.confidence ∈ [0,1] and
provenance{source, ref, source_kinds}.legacy_components[] is non-null, never dropped — the SymbolIds the requirement
covers.disposition ∈ {keep, modify, drop, new}; a drop needs a disposition_reason.RULE-/VAL-/ERR- + 3–6 zero-padded digits, unique within a requirement.metadata.schema_version == "1.0.0"._clients.py seam.development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
development
Coverage evaluator + pre-build threat model for the domain-extraction workflow (CONTRACT-3 §2). Emits `coverage-report.json` from the estate store, then adversarially reviews the extracted domain model: hunts missing error paths, ungrounded rules, reason-less drops, cross-cluster smears, and coverage holes. Use when: dispatched as the `coverage` phase of a domain-extraction workflow run. The phase runs in a git worktree; WICKED_ESTATE_DB points at the live estate store. NOT for mining rules (domain-extractor) or grouping domains (domain-modeler). This worker EMITS coverage evidence AND CRITIQUES the domain model.