Generate quality validation checklist from spec, plan, and tasks. Use after creating tasks. Triggers on: create checklist, quality checklist, validation checklist.
Generate domain-specific quality checklists to validate implementation completeness.
This skill runs after tasks, before analyze:
specify → plan → tasks → checklist → analyze → implement
Purpose:
Every generated checklist MUST include these testing items:
These items are non-negotiable and must appear in every checklist.
Every story in the checklist MUST include:
bun run typecheck passes with 0 errorsbun run lint passes with 0 errors AND 0 warningsbun test passesAll three commands must pass - no exceptions.
Every checklist MUST include:
checklist.mdImportant: Checklist items get merged into prd.json acceptance criteria!
Verify these files exist:
relentless/features/NNN-feature/spec.mdrelentless/features/NNN-feature/plan.mdrelentless/features/NNN-feature/tasks.mdRead:
relentless/constitution.md - Quality standards and requirementsCreate 7-10 categories based on feature domain:
Mandatory Categories (always include):
Common Categories (include as needed):
For each category, create 5-10 specific validation items:
Format:
- [ ] CHK-001 [US-001] Specific, testable requirement
- [ ] CHK-002 [Gap] Missing specification identified
- [ ] CHK-003 [Ambiguity] Unclear requirement needs clarification
- [ ] CHK-004 [Edge Case] Potential edge case to handle
Guidelines:
[US-XXX]Ensure checklist includes items for constitution MUST rules:
any types)relentless/features/NNN-feature/checklist.md.claude/skills/validators/scripts/validate-checklist.sh "relentless/features/NNN-feature/checklist.md"
/relentless.convert (if not done) or /relentless.analyze# Quality Checklist: User Authentication
**Purpose:** Validate completeness of user authentication implementation
**Created:** 2026-01-11
**Feature:** [spec.md](./spec.md)
## 0. Quality Gates (MANDATORY - Every Story)
- [ ] CHK-001 `bun run typecheck` passes with 0 errors
- [ ] CHK-002 `bun run lint` passes with 0 errors AND 0 warnings
- [ ] CHK-003 `bun test` passes
- [ ] CHK-004 No debug code (console.log, debugger statements)
- [ ] CHK-005 No unused imports or variables
## 1. TDD Compliance (MANDATORY)
- [ ] CHK-006 Tests written BEFORE implementation code
- [ ] CHK-007 Tests verified to FAIL before writing implementation
- [ ] CHK-008 Unit test coverage ≥80%
- [ ] CHK-009 Integration tests for all API endpoints
- [ ] CHK-010 E2E tests for complete user flows
## 2. Routing Compliance (MANDATORY)
- [ ] CHK-011 Routing preference documented in spec.md
- [ ] CHK-012 prd.json has routing metadata for all stories
- [ ] CHK-013 Complexity classifications correct for story scope
- [ ] CHK-014 Estimated costs are reasonable
- [ ] CHK-015 Mode selection appropriate for complexity
## 3. Schema & Database
- [ ] CHK-016 [US-001] User table has all required fields (id, email, password_hash, confirmed, timestamps)
- [ ] CHK-017 [US-001] Email field has UNIQUE constraint
- [ ] CHK-018 [US-001] Indexes created on frequently queried fields (email)
- [ ] CHK-019 [Gap] Consider adding last_login_at timestamp for analytics
- [ ] CHK-020 [US-001] Migration script tested on clean database
## 4. Backend Logic
- [ ] CHK-021 [US-001] Password hashing uses bcrypt with appropriate cost factor
- [ ] CHK-022 [US-001] Email validation prevents common typos and invalid formats
- [ ] CHK-023 [US-002] JWT tokens include user ID and expiration
- [ ] CHK-024 [US-002] Token verification handles expired tokens gracefully
- [ ] CHK-025 [Ambiguity] Password reset flow not specified - out of scope?
## 5. API Integration
- [ ] CHK-026 [US-001] POST /api/auth/register returns 201 on success
- [ ] CHK-027 [US-001] Register endpoint returns 400 for invalid email
- [ ] CHK-028 [US-001] Register endpoint returns 409 for duplicate email
- [ ] CHK-029 [US-002] POST /api/auth/login returns 401 for wrong password
- [ ] CHK-030 [US-002] Login endpoint returns 403 for unconfirmed account
- [ ] CHK-031 [Edge Case] Rate limiting on auth endpoints to prevent brute force
## 6. Testing & Validation
- [ ] CHK-032 [US-001] Unit tests for password hashing utility
- [ ] CHK-033 [US-001] Unit tests for email validation
- [ ] CHK-034 [US-002] Integration test for full registration flow
- [ ] CHK-035 [US-002] Integration test for login flow
- [ ] CHK-036 [US-003] E2E test for email confirmation
- [ ] CHK-037 [Constitution] Test coverage meets minimum 80% requirement
## 7. Security & Permissions
- [ ] CHK-038 [US-001] Passwords never logged or exposed in errors
- [ ] CHK-039 [US-001] Password requirements enforced (min length, complexity)
- [ ] CHK-040 [US-002] JWT secret stored in environment variable, not code
- [ ] CHK-041 [US-002] Token expiration validated on every request
- [ ] CHK-042 [Gap] Consider adding account lockout after N failed attempts
## 8. Performance & UX
- [ ] CHK-043 [US-001] Registration completes within 2 seconds
- [ ] CHK-044 [US-002] Login completes within 1 second
- [ ] CHK-045 [US-003] Confirmation email sent within 30 seconds
- [ ] CHK-046 [Edge Case] Graceful handling when email service is down
## 9. Documentation
- [ ] CHK-047 API endpoints documented with examples
- [ ] CHK-048 Environment variables documented in README
- [ ] CHK-049 Database schema documented
[US-XXX] tags[Gap] and [Ambiguity] tags