ddd-validate
Validate domain boundaries -- detect cross-context import violations and aggregate invariant issues. Use when auditing a DDD codebase for leaks between bounded contexts, before merging cross-cutting changes, or as a CI gate to catch boundary erosion early.
How do I install this agent skill?
npx skills add https://github.com/ruvnet/ruflo --skill ddd-validateIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
This skill performs Domain-Driven Design (DDD) validation by scanning TypeScript files for boundary violations. It executes several shell commands and downloads an external CLI tool (@claude-flow/cli) at runtime. The skill also faces indirect prompt injection risks by processing untrusted source code without sanitization.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Validate domain boundary integrity across all bounded contexts.
Steps
-
Discover contexts: Scan
src/*/domain/to find all bounded contexts. -
Check cross-boundary violations:
- For each context, scan all
.tsfiles for import statements - Flag any import that reaches into another context's
domain/directory directly - Allowed: importing from another context's public
index.ts(application layer) - Violation: importing from
src/<other-context>/domain/entities/...directly
# Find cross-boundary imports for ctx in $(find src -maxdepth 2 -name "domain" -type d | sed 's|src/||;s|/domain||'); do grep -rn "from ['\"].*src/" "src/$ctx/" --include="*.ts" | grep -v "src/$ctx/" || true done - For each context, scan all
-
Check aggregate invariant enforcement:
- Scan aggregate root entities for public setters that bypass validation
- Flag mutable public properties without invariant checks
- Verify that child entities are not directly accessible (must go through aggregate root)
-
Check event naming conventions:
- Domain events should be past-tense named (e.g.,
OrderCreated, notCreateOrder) - Events should be immutable (no public setters)
- Events should carry the aggregate ID
- Domain events should be past-tense named (e.g.,
-
Check repository patterns:
- Repository interfaces should exist in
domain/repositories/, notinfrastructure/ - Repository implementations should exist in
infrastructure/, notdomain/ - Each aggregate root should have exactly one repository
- Repository interfaces should exist in
-
Report findings:
- Output a table of violations with file path, line number, violation type, and suggestion
- Categorize as:
BOUNDARY,INVARIANT,EVENT,REPOSITORY - Exit with summary: total violations, by category, severity
-
Store results:
npx @claude-flow/cli@latest memory store --key "ddd-validation-TIMESTAMP" --value "RESULTS_SUMMARY" --namespace tasks npx @claude-flow/cli@latest hooks post-task --task-id "ddd-validate" --success true --store-results true
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/ruvnet/ruflo/ddd-validate">View ddd-validate on skillZs</a>