Code quality orchestrator enforcing TRUST 5 validation, proactive code analysis, linting standards, and automated best practices. Use when performing code review, quality gate checks, lint configuration, TRUST 5 compliance validation, or establishing coding standards. Do NOT use for writing tests (use moai-workflow-testing instead) or debugging runtime errors (use expert-debug agent instead).
This skill provides background knowledge on MoAI's quality model: the five
TRUST 5 principles, how agents enforce them, the 3-level harness, and the
language-aware toolchains that /moai gate runs. MoAI does NOT ship a
quality-validation library — quality is enforced through agents
(manager-develop, sync-auditor), slash commands (/moai gate,
/moai review), and the harness (minimal/standard/thorough).
TRUST 5 Principles (Tested, Readable, Unified, Secured, Trackable) are quality dimensions, not code objects. Every code change is evaluated against all five.
Quality Mechanisms (the real enforcement layer):
/moai gate — runs lint + format + type-check + test in parallel as a
pre-commit quality gate (<30s). Auto-detects the project language and runs
the appropriate toolchain.manager-develop (run-phase) — implements via cycle_type ∈ {tdd, ddd,
autofix}; the chosen cycle shapes how tests and behavior are produced.sync-auditor — independent skeptical quality assessment with 4-dimension
scoring (Functionality, Security, Craft, Consistency), scored as the
harmonic mean of dimensions, not the average.MoAI does not provide a Python SDK or any library for quality validation. Quality is enforced through the workflow, the agents, and the gate commands. This skill documents how those pieces fit together so a Claude invocation can reason about quality correctly.
| Phase | Quality check | Owner | |-------|--------------|-------| | plan | Capture LSP baseline; identify quality risks in the plan | manager-spec | | run | Zero errors/type-errors/lint-errors; tests pass; coverage met | manager-develop (cycle_type shapes the approach) | | sync | Lint clean (≤10 warnings); docs updated; TRUST 5 re-affirmed | manager-docs, then sync-auditor scores | | audit | Independent 4-dimension scoring (Functionality/Security/Craft/Consistency) | sync-auditor |
The run-phase cycle_type selects how quality is built in:
/moai fix and regression recovery.See Skill("moai-workflow-tdd"), Skill("moai-workflow-ddd"), and Skill("moai-workflow-loop") for the per-cycle mechanics.
TRUST 5 is a mnemonic for five quality dimensions. Treat each as a question to ask of any change, not a score to compute.
For the per-principle assessment checklist and the "not applicable" guard, see TRUST 5 Principles.
The harness level controls how deep quality validation goes. It is auto-determined by the Complexity Estimator based on SPEC scope.
| Level | What runs | When | |-------|-----------|------| | minimal | Fast validation only (lint + type + test) | Small SPECs, low risk | | standard | Default checks (lint + type + test + format) | Most SPECs | | thorough | Full sync-auditor + 4-dimension TRUST 5 scoring | Large SPECs, high risk |
/moai gate is the lightweight pre-commit entry point: it runs lint +
format + type-check + test in parallel and applies no fixes. It is the
fastest way to get a quality signal. For deeper review use /moai review.
The quality gate auto-detects the project language and runs the appropriate toolchain. Tools that are not installed are skipped gracefully; projects with no recognized language marker pass the gate silently. This skill is language-neutral — the 16 supported languages are treated equally.
| Language | Lint | Format | Test | |----------|------|--------|------| | Go | go vet → golangci-lint | gofmt | go test | | Python | ruff | black | pytest | | TypeScript / JavaScript | eslint | prettier | jest / mocha | | Rust | cargo clippy | rustfmt | cargo test | | Java / Kotlin | (per project linter) | (per project) | junit | | Ruby | rubocop | rubocop | rspec | | PHP | phpstan / phpcs | php-cs-fixer | pest / phpunit | | ... | (16 languages supported; auto-detected) | | |
For the full toolchain mapping and how /moai gate detects the language,
see Language-Aware Toolchains.
Each module is loaded on demand. Load the one relevant to the current task.
/moai gate,
/moai review, and /moai loop surface quality issues proactively, and
how to triage findings.Agents (see CLAUDE.md §4 for the 11-agent catalog):
manager-develop — run-phase implementation; owns the Tested and Unified
principles through cycle_type.sync-auditor — independent 4-dimension quality scoring (Functionality /
Security / Craft / Consistency).Explore (Anthropic built-in) — read-only codebase exploration before
assessing quality.Skills:
moai-foundation-core — TRUST 5 framework cross-reference and SPEC
workflow foundations.moai-ref-testing-pyramid — test-pyramid strategy, coverage targets, and
test patterns.moai-ref-owasp-checklist — OWASP Top 10 security checklist for the
Secured principle.moai-workflow-tdd / moai-workflow-ddd / moai-workflow-loop — the
cycle_type workflows that manager-develop uses.Commands:
/moai gate — pre-commit quality gate (lint + format + type + test)./moai review — code review with security and MX-tag compliance./moai fix — auto-detect and fix LSP/lint/type errors./moai loop — iterative fix loop until resolved or max iterations.| Rationalization | Reality | |---|---| | "The linter warnings are false positives" | False positives should be suppressed with inline comments. Ignoring them trains the team to ignore real issues. | | "Security scanning can wait until before release" | Security vulnerabilities compound. Late discovery means expensive rework. Scan continuously. | | "Coverage is high enough, the remaining 15% is edge cases" | Edge cases are where production bugs live. The uncovered code is the riskiest code. | | "Code review is subjective, automation is sufficient" | Automation catches syntax and patterns. Reviews catch design flaws, naming confusion, and missing abstractions. | | "TRUST 5 is too bureaucratic for a hotfix" | Hotfixes without quality gates introduce the next hotfix. TRUST 5 on a hotfix is the minimum, not the maximum. |
Chesterton's Fence: Before removing a quality check, understand why it was added. Removing a gate without understanding its history repeats the failure it was designed to prevent.
Shift Left: The earlier a defect is found, the cheaper it is to fix. Quality checks belong in the development loop, not at the end of it.
<!-- moai:evolvable-end --> <!-- moai:evolvable-start id="red-flags" -->npx skills add modu-ai/moai-foundation-quality下载完整 Skill 目录,包含 SKILL.md 及所有相关文件
Search for places (restaurants, cafes, etc.) via Google Places API proxy on localhost.
Interact with GitHub using the `gh` CLI. Use `gh issue`, `gh pr`, `gh run`, and `gh api` for issues, PRs, CI runs, and advanced queries.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
Start voice calls via the OpenClaw voice-call plugin.
Notion API for creating and managing pages, databases, and blocks.
Gemini CLI for one-shot Q&A, summaries, and generation.
Category:developer