skills/platform/SKILL.md
Platform domain skill: security scanning, incident triage, infrastructure review, and distributed-trace analysis. Routes to one of four inline actions (security | incident | infra | traces) backed by the rubrics in refs/, and links out to the domain's sub-skills (audit, compliance, health, observability, CI/CD tooling, peer-health) and fork workers. Use when: "security scan", "vulnerability assessment", "scan this PR for vulnerabilities", "run the security scanners", "incident", "production is down", "triage this alert", "root cause this error", "review our Terraform", "IaC review", "infrastructure review", "cloud cost review", "trace analysis", "why is this endpoint slow", "latency investigation", or any former /wicked-garden:platform:{security|incident|infra|traces} invocation.
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-platformInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
One entry point for the platform domain. Pick the action from the request, parse its args, load its ref, and apply it inline.
| Action | Use for | Args | Ref |
|--------|---------|------|-----|
| security | Real-scanner vulnerability scan + triage on code, PRs, or full repos | <path, PR, or 'full'> [--scenarios] | refs/security-scan.md |
| incident | Rapid incident triage: root cause, blast radius, remediation | <error message, alert, or symptom> | incident/refs/incident.md |
| infra | IaC / cloud architecture review: security, cost, HA, best practice | <path to IaC files or 'scan'> | infra/refs/infra.md |
| traces | Distributed-trace analysis: latency, dependencies, bottlenecks | [service, trace ID, or 'slow'] | traces/refs/traces.md |
Routing hints:
audit sub-skill, not security.compliance sub-skill.health sub-skill.observability sub-skill.arch), not infra.Run the real security scanners, then triage their actual output. This action does NOT grep-guess: it detects which scanners are installed, runs the ones that exist, and feeds their findings to triage. A missing scanner is reported and skipped — the action never fails because a tool is absent.
., or the PR's changed files
when given a PR number). Note --scenarios if passed.Read("${CLAUDE_PLUGIN_ROOT}/skills/platform/refs/security-scan.md") — the
scanner detect+run block, the report formats for each scanner's JSON
output, and the triage step.--scenarios behaviour, bus emit), read
${CLAUDE_PLUGIN_ROOT}/skills/platform-security-engineer/SKILL.md — your
reference, NOT a thing to re-derive.NOT for compliance evidence collection (use the audit sub-skill) or IaC
posture (use the infra action).
Rapid incident triage with root cause correlation, blast radius assessment, and remediation guidance.
Scope: this action is for rapid active triage — root cause, blast radius, remediation steps. To log an incident against a crew project with traceability, use the crew incident flow (
crew:incident) instead.
Read("${CLAUDE_PLUGIN_ROOT}/skills/platform/incident/refs/incident.md") —
the 5-phase rubric (triage → stabilize → investigate → resolve →
follow-up), severity classification, common patterns, output format, and
communication templates.ListMcpResourcesTool, correlate with recent git changes, classify
severity (SEV1–SEV4), and produce the incident report with blast radius,
mitigation actions, and rollback decision.Review infrastructure-as-code and cloud architecture for security, cost, HA,
and best-practice posture. NOT for application architecture review (use the
engineering domain's arch review) or active incident response (use the
incident action).
scan to discover .tf, .tfvars,
CloudFormation, Pulumi, Kubernetes manifests, and docker-compose files.Read("${CLAUDE_PLUGIN_ROOT}/skills/platform/infra/refs/infra.md") —
discovery commands, security matrix, cost-optimization checklist, HA/DR
checklist, platform best practices (Terraform, Kubernetes, Docker
Compose), and output format.Analyze distributed traces for latency investigation, service dependencies,
and bottleneck detection. This is distributed tracing across services —
for wicked-garden hook execution traces, use the observability sub-skill
(scripts/platform/observability/ops_log_viewer.py).
slow for p99 latency
investigation.Read("${CLAUDE_PLUGIN_ROOT}/skills/platform/traces/refs/traces.md") —
tracing source discovery, investigation checklist, fallback code-pattern
analysis, common patterns (N+1, sequential fan-out, cold-start), and
output format.ListMcpResourcesTool, query the target, and produce the trace analysis
with latency breakdown, service dependencies, bottlenecks, and
optimization recommendations with expected impact.Loaded on demand — each is its own skill beside this one:
| Sub-skill | Use for |
|-----------|---------|
| skills/platform/audit/ | Audit evidence collection for SOC2/HIPAA/GDPR/PCI |
| skills/platform/compliance/ | Regulatory compliance check against a framework |
| skills/platform/errors/ | Production error spike/pattern investigation |
| skills/platform/health/ | System health aggregation across services |
| skills/platform/observability/ | Plugin ecosystem diagnostics: probes, hook traces, contract assertions, toolchain discovery |
| skills/platform/gh-cli/ | Advanced gh CLI operations (workflows, PRs, releases, repo) |
| skills/platform/glab-cli/ | Advanced glab CLI operations for GitLab |
| skills/platform/github-actions/ | GitHub Actions workflow generation/optimization/troubleshooting |
| skills/platform/gitlab-ci/ | GitLab CI/CD pipeline writing |
| skills/platform/prereq-doctor/ | Missing tool/dependency diagnosis |
| skills/platform/gate-benchmark-rebaseline/ | AC-11 gate-result benchmark re-baselining |
| skills/platform/peer-health/ | wicked-* peer tool reachability + version health |
Dispatchable specialist workers (context: fork), for delegated deep passes:
skills/platform-security-engineer/ — security scanning + vulnerability
assessment (also the triage rubric for the security action)skills/platform-compliance-officer/ — regulatory compliance analysisskills/platform-privacy-expert/ — PII/PHI detection and privacy-by-designdevelopment
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).