Enterprise code quality orchestrator with TRUST 5 validation, proactive analysis, and automated best practices enforcement
This skill provides background knowledge on MoAI's quality model: the five
TRUST 5 principles, how agents enforce them, the 3-level harness, and the
language-aware toolchains that /moai gate runs. MoAI does NOT ship a
quality-validation library โ quality is enforced through agents
(manager-develop, sync-auditor), slash commands (/moai gate,
/moai review), and the harness (minimal/standard/thorough).
TRUST 5 Principles (Tested, Readable, Unified, Secured, Trackable) are quality dimensions, not code objects. Every code change is evaluated against all five.
Quality Mechanisms (the real enforcement layer):
/moai gate โ runs lint + format + type-check + test in parallel as a
pre-commit quality gate (<30s). Auto-detects the project language and runs
the appropriate toolchain.manager-develop (run-phase) โ implements via cycle_type โ {tdd, ddd,
autofix}; the chosen cycle shapes how tests and behavior are produced.sync-auditor โ independent skeptical quality assessment with 4-dimension
scoring (Functionality, Security, Craft, Consistency), scored as the
harmonic mean of dimensions, not the average.MoAI does not provide a Python SDK or any library for quality validation. Quality is enforced through the workflow, the agents, and the gate commands. This skill documents how those pieces fit together so a Claude invocation can reason about quality correctly.
| Phase | Quality check | Owner |
|---|---|---|
| plan | Capture LSP baseline; identify quality risks in the plan | manager-spec |
| run | Zero errors/type-errors/lint-errors; tests pass; coverage met | manager-develop (cycle_type shapes the approach) |
| sync | Lint clean (โค10 warnings); docs updated; TRUST 5 re-affirmed | manager-docs, then sync-auditor scores |
| audit | Independent 4-dimension scoring (Functionality/Security/Craft/Consistency) | sync-auditor |
The run-phase cycle_type selects how quality is built in:
/moai fix and regression recovery.See Skill("moai-workflow-tdd"), Skill("moai-workflow-ddd"), and Skill("moai-workflow-loop") for the per-cycle mechanics.
TRUST 5 is a mnemonic for five quality dimensions. Treat each as a question to ask of any change, not a score to compute.
For the per-principle assessment checklist and the "not applicable" guard, see TRUST 5 Principles.
The harness level controls how deep quality validation goes. It is auto-determined by the Complexity Estimator based on SPEC scope.
| Level | What runs | When |
|---|---|---|
| minimal | Fast validation only (lint + type + test) | Small SPECs, low risk |
| standard | Default checks (lint + type + test + format) | Most SPECs |
| thorough | Full sync-auditor + 4-dimension TRUST 5 scoring | Large SPECs, high risk |
/moai gate is the lightweight pre-commit entry point: it runs lint +
format + type-check + test in parallel and applies no fixes. It is the
fastest way to get a quality signal. For deeper review use /moai review.
The quality gate auto-detects the project language and runs the appropriate toolchain. Tools that are not installed are skipped gracefully; projects with no recognized language marker pass the gate silently. This skill is language-neutral โ the 16 supported languages are treated equally.
| Language | Lint | Format | Test |
|---|---|---|---|
| Go | go vet โ golangci-lint | gofmt | go test |
| Python | ruff | black | pytest |
| TypeScript / JavaScript | eslint | prettier | jest / mocha |
| Rust | cargo clippy | rustfmt | cargo test |
| Java / Kotlin | (per project linter) | (per project) | junit |
| Ruby | rubocop | rubocop | rspec |
| PHP | phpstan / phpcs | php-cs-fixer | pest / phpunit |
| ... | (16 languages supported; auto-detected) |
For the full toolchain mapping and how /moai gate detects the language,
see Language-Aware Toolchains.
Each module is loaded on demand. Load the one relevant to the current task.
/moai gate,
/moai review, and /moai loop surface quality issues proactively, and
how to triage findings.Agents (see CLAUDE.md ยง4 for the 11-agent catalog):
manager-develop โ run-phase implementation; owns the Tested and Unified
principles through cycle_type.sync-auditor โ independent 4-dimension quality scoring (Functionality /
Security / Craft / Consistency).Explore (Anthropic built-in) โ read-only codebase exploration before
assessing quality.Skills:
moai-foundation-core โ TRUST 5 framework cross-reference and SPEC
workflow foundations.moai-ref-testing-pyramid โ test-pyramid strategy, coverage targets, and
test patterns.moai-ref-owasp-checklist โ OWASP Top 10 security checklist for the
Secured principle.moai-workflow-tdd / moai-workflow-ddd / moai-workflow-loop โ the
cycle_type workflows that manager-develop uses.Commands:
/moai gate โ pre-commit quality gate (lint + format + type + test)./moai review โ code review with security and MX-tag compliance./moai fix โ auto-detect and fix LSP/lint/type errors./moai loop โ iterative fix loop until resolved or max iterations.| Rationalization | Reality |
|---|---|
| "The linter warnings are false positives" | False positives should be suppressed with inline comments. Ignoring them trains the team to ignore real issues. |
| "Security scanning can wait until before release" | Security vulnerabilities compound. Late discovery means expensive rework. Scan continuously. |
| "Coverage is high enough, the remaining 15% is edge cases" | Edge cases are where production bugs live. The uncovered code is the riskiest code. |
| "Code review is subjective, automation is sufficient" | Automation catches syntax and patterns. Reviews catch design flaws, naming confusion, and missing abstractions. |
| "TRUST 5 is too bureaucratic for a hotfix" | Hotfixes without quality gates introduce the next hotfix. TRUST 5 on a hotfix is the minimum, not the maximum. |
Chesterton's Fence: Before removing a quality check, understand why it was added. Removing a gate without understanding its history repeats the failure it was designed to prevent.
Shift Left: The earlier a defect is found, the cheaper it is to fix. Quality checks belong in the development loop, not at the end of it.