Devrites api interface
Skill ViktorsBaikers/DevRites/pack/generated/codex/skills/devrites-api-interface
Stop your AI from shipping half-baked code. A disciplined senior-engineer workflow for Claude Code (spec, vet, build, prove, review, seal, ship) that keeps each feature's state on disk, catches spec drift mid-build, gates every phase on your project's principles, and refuses to claim "done" without proof.
npx -y skills add ViktorsBaikers/DevRites --skill devrites-api-interfaceAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Internal DevRites skill; DevRites agents invoke it explicitly, not by prompt match.
SKILL.md
7.0 KB, as published. Nobody here has run it
Codex compatibility
This is the Codex mirror of a DevRites skill. In Codex:
- Load DevRites engineering standards from
.agents/skills/devrites-lib/reference/standards/. Read.agents/skills/devrites-lib/reference/standards/core.mdbefore workflow work, then load the other.agents/skills/devrites-lib/reference/standards/*.mdfiles exactly when this skill asks for them. - Installed
.agents/mirrors may be Git-ignored. If a repository-aware file tool refuses an ignored path, read it with a native filesystem command instead; a tool refusal is not a completed task. - For automatic Engram calls, omit optional
projectandsession_idunless an exact value came from Engram or repository configuration. Never derive either fromtask_name, a run ID, directory name, or normalized slug. Callmem_session_summarywithout them by default; onunknown_sessionorunknown_project, retry once with both optional fields omitted. If auto-detection is ambiguous, ask the user instead of guessing. - Use the installed
devrites-enginebinary as the canonical runtime helper surface for orientation, gates, and state mutation. - Invocation and dispatch are different: invoke means run a skill in this context; dispatch means start a fresh agent with
spawn_agent, await it, and reconcile its result. Never describe inline skill work as a dispatch. - On MultiAgent V2, call
spawn_agentwith the exact namedagent_type=devrites-<role>, a uniquetask_name, andfork_turns="none". A missing visibleagent_typefield is still V2—not capability loss, V1, or HITL—so send it anyway. If the named call rejects it, stop before any generic/default spawn. Codex loads the role TOML'sdeveloper_instructionsnatively; DevRites verifies the durable rollout, wait, completion, and delivered result. - Only after the runtime explicitly identifies MultiAgent V1, use generic
explorerfor a read-only role withfork_turns="none"and name exactly one.codex/agents/devrites-<role>.tomlcontract in the message. Trusted.codex/hooks.jsoninjects that contract's exactdeveloper_instructionsand binds the child to the fail-closed reviewer read-only guard. - On explicitly identified MultiAgent V1,
devrites-slice-wrightuses genericworkerwithfork_turns="none"and the exact role TOML named in the message. Trusted.codex/hooks.jsonbinds it to the active reconcile window and.wright-allowlist. - The invoked skill's
required-agent-rolesfrontmatter arms the fail-closed Stop receipt. Every listed role must have a confirmed start, wait, and non-empty result in this turn. - If the required dispatch for the explicitly identified runtime is unavailable or rejected, stop for HITL. Never switch runtime lanes. Never execute a DevRites specialist role in the root context.
- Wait for every required fresh-context dispatch before reconciling or advancing. A backgrounded or lost result is incomplete.
- Codex project hooks are installed in
.codex/hooks.json; declared-leaf hooks are scoped inside.codex/agents/devrites-*.toml. Review and trust them with/hooksbefore relying on hook enforcement. - When this skill asks a HITL question via
AskUserQuestion: Codex's equivalent (request_user_input) exists only in Plan mode. Outside Plan mode, render the option set as a plain numbered list in chat and end the turn so the human answers: NEVER silently pick an option yourself; auto-picking is AFK's contract, gated by the.devrites/AFKsentinel.
devrites-api-interface: contract before implementation
When a slice crosses a boundary (FE/BE, service/service, module/module) or exposes a public interface, define the contract first so both sides can proceed and the interface stays stable.
Define the contract first
- Shape: request/response or function signature; field names, types, optionality, units. Follow the project's existing naming and conventions.
- Status & errors: success codes, error codes, error body shape, validation messages. Errors are part of the contract, not an afterthought.
- Semantics: idempotency, pagination, ordering, nullability, side effects.
- Versioning/compat: is this new or a change to an existing contract? A breaking change to an existing consumer is a user decision (and a drift event if unplanned).
Stability principles
- Design for the caller. The interface should make the common case easy and the wrong call hard.
- Prefer addition over modification. A new field is additive and optional; changing a
field's type or removing one is a breaking change. You can add later. You can't un-ship a
shape consumers already read (observable behavior is the contract:
deprecation.mdHyrum's law). - One-Version Rule. Design as if only one version of this interface will ever exist: extend the single contract rather than fork a v2 you then maintain in parallel. Forking multiplies the surface and breeds diamond-dependency conflicts; bump a version only when an addition genuinely can't stay backward-compatible.
- Match existing endpoints/modules in style: don't introduce a competing convention.
- Validate at the boundary, and only there (untrusted → trusted); don't trust
caller-supplied trust signals (IDs, roles). Validation does not belong between two internal
typed functions, on your own database's data, or in a utility already called by validated code.
A check inside the trusted core hides the bug in the boundary that should have caught it. A
third-party API response is external input: always untrusted. (Three-tier boundary:
security.md; seerite-review/reference/security-review.md.)
Type craft: make the wrong call unrepresentable
- Brand your ids. A bare
string/numberid is assignable to any other id, so the compiler won't stop you passing auserIdwhere ataskIdis due. Give each a nominal brand (type TaskId = string & { readonly __brand: 'TaskId' }) and the mix-up becomes a type error, not a production incident. - Model variants as discriminated unions, each state carrying only its own fields, so an impossible combination can't be constructed in the first place.
Enables the split
A clear contract lets $rite-plan split proceed: the backend slice can land against the
contract with a stub consumer; the frontend slice can build against a mock or the real
contract. Neither side blocks on the other.
Doubt the contract
Before standing the interface, run devrites-doubt: boundary decisions are exactly the
non-trivial kind worth an adversarial check.
Done when
The contract is complete only when every field carries a type + optionality + unit,
every success and error status code is enumerated with its error-body shape, the
devrites-doubt verdict is accept, and the contract + rationale are recorded in
decisions.md. A contract that pins only the happy-path shape is not done.