tdd-refactor
Improve code quality, apply security best practices, and enhance design whilst maintaining green tests and GitHub issue compliance.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 247eeef964e3c25b… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
tdd-refactor.md
TDD Refactor Phase - Improve Quality & Security
Clean up code, apply security best practices, and enhance design whilst keeping all tests green and maintaining GitHub issue compliance.
GitHub Issue Integration
Issue Completion Validation
- Verify all acceptance criteria met - Cross-check implementation against GitHub issue requirements
- Update issue status - Mark issue as completed or identify remaining work
- Document design decisions - Comment on issue with architectural choices made during refactor
- Link related issues - Identify technical debt or follow-up issues created during refactoring
Quality Gates
- Definition of Done adherence - Ensure all issue checklist items are satisfied
- Security requirements - Address any security considerations mentioned in issue
- Performance criteria - Meet any performance requirements specified in issue
- Documentation updates - Update any documentation referenced in issue
Core Principles
Code Quality Improvements
- Remove duplication - Extract common code into reusable methods or classes
- Improve readability - Use intention-revealing names and clear structure aligned with issue domain
- Apply SOLID principles - Single responsibility, dependency inversion, etc.
- Simplify complexity - Break down large methods, reduce cyclomatic complexity
Security Hardening
- Input validation - Sanitise and validate all external inputs per issue security requirements
- Authentication/Authorisation - Implement proper access controls if specified in issue
- Data protection - Encrypt sensitive data, use secure connection strings
- Error handling - Avoid information disclosure through exception details
- Dependency scanning - Check for vulnerable NuGet packages
- Secrets management - Use Azure Key Vault or user secrets, never hard-code credentials
- OWASP compliance - Address security concerns mentioned in issue or related security tickets
Design Excellence
- Design patterns - Apply appropriate patterns (Repository, Factory, Strategy, etc.)
- Dependency injection - Use DI container for loose coupling
- Configuration management - Externalise settings using IOptions pattern
- Logging and monitoring - Add structured logging with Serilog for issue troubleshooting
- Performance optimisation - Use async/await, efficient collections, caching
C# Best Practices
- Nullable reference types - Enable and properly configure nullability
- Modern C# features - Use pattern matching, switch expressions, records
- Memory efficiency - Consider Span, Memory for performance-critical code
- Exception handling - Use specific exception types, avoid catching Exception
Security Checklist
- Input validation on all public methods
- SQL injection prevention (parameterised queries)
- XSS protection for web applications
- Authorisation checks on sensitive operations
- Secure configuration (no secrets in code)
- Error handling without information disclosure
- Dependency vulnerability scanning
- OWASP Top 10 considerations addressed
Execution Guidelines
- Review issue completion - Ensure GitHub issue acceptance criteria are fully met
- Ensure green tests - All tests must pass before refactoring
- Confirm your plan with the user - Ensure understanding of requirements and edge cases. NEVER start making changes without user confirmation
- Small incremental changes - Refactor in tiny steps, running tests frequently
- Apply one improvement at a time - Focus on single refactoring technique
- Run security analysis - Use static analysis tools (SonarQube, Checkmarx)
- Document security decisions - Add comments for security-critical code
- Update issue - Comment on final implementation and close issue if complete
Refactor Phase Checklist
- GitHub issue acceptance criteria fully satisfied
- Code duplication eliminated
- Names clearly express intent aligned with issue domain
- Methods have single responsibility
- Security vulnerabilities addressed per issue requirements
- Performance considerations applied
- All tests remain green
- Code coverage maintained or improved
- Issue marked as complete or follow-up issues created
- Documentation updated as specified in issue
Files
1- tdd-refactor.md
5e556f4ca24.6 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from davila7/claude-code-templates8
3D art and asset creation specialist for game development. Use PROACTIVELY for 3D modeling, texturing, animation, asset optimization, and technical art workflows for Unity and Unreal Engine.
GPT 4.1 as a top-notch coding agent.
An agent designed to assist with software development tasks for .NET projects.
Ultimate Transparent Thinking Beast Mode
Support development of .NET (OOP) WinForms Designer compatible Apps.
>-
>-
Expert assistant for web accessibility (WCAG 2.1/2.2), inclusive UX, and a11y testing
Related methodology skillsscan passed
Use when the user wants to analyze retention, cohort behavior, engagement trends, or understand how different user groups perform over time. Triggers on: 'cohort analysis', 'retention analysis', 'user retention', 'cohort retention', 'week 1 retention', 'retention curve'.
Use this agent when you need to analyze code comments for accuracy, completeness, and long-term maintainability. This includes (1) after generating large documentation comments or docstrings, (2) before finalizing a pull request that adds or modifies comments, (3) when reviewing existing comments fo
Research a company from its URL or description to infer Stripe Connect integration shape
Senior code reviewer that evaluates changes across five dimensions — correctness, readability, architecture, security, and performance. Use for thorough code review before merge.
Checks one documented requirement against the code that should implement it, and returns a verdict with the lines that evidence it. Writes its analysis to disk and returns a compact record. Use for a single requirement; use the spec-compliance workflow for a whole document.
Technical documentation architect that analyzes repositories and generates structured wiki catalogues with onboarding guides