Clean Code Standard — Quick Reference
This skill is the authoritative clean code standard for this repository's shared skills. It defines stable rule IDs (CC-*), how to apply them in reviews, and how to extend them safely via language overlays and explicit exceptions.
Modern Best Practices (January 2026): Prefer small, reviewable changes and durable change context (https://google.github.io/eng-practices/review/developer/small-cls.html, https://google.github.io/eng-practices/review/developer/cl-descriptions.html). Use normative language consistently (RFC 2119: https://www.rfc-editor.org/rfc/rfc2119). Treat security-by-design and secure defaults as baseline (OWASP Top 10: https://owasp.org/www-project-top-ten/, NIST SSDF SP 800-218: https://csrc.nist.gov/pubs/sp/800/218/final). Build observable systems (OpenTelemetry: https://opentelemetry.io/docs/). For current tool choices, consult data/sources.json.
Quick Reference
| Task |
Tool/Framework |
Command |
When to Use |
| Cite a standard |
CC-* rule ID |
N/A |
PR review comments, design discussions, postmortems |
| Categorize feedback |
CC-NAM, CC-ERR, CC-SEC, etc. |
N/A |
Keep feedback consistent without "style wars" |
| Add stack nuance |
Language overlay |
N/A |
When the base rule is too generic for a language/framework |
| Allow an exception |
Waiver record |
N/A |
When a rule must be violated with explicit risk |
| Reuse shared checklists |
assets/checklists/ |
N/A |
When you need product-agnostic review/release checklists |
| Reuse utility patterns |
utilities/ |
N/A |
When extracting shared auth/logging/errors/resilience/testing utilities |
When to Use This Skill
- Defining or enforcing clean code rules across teams and languages.
- Reviewing code: cite
CC-* IDs and avoid restating standards in reviews.
- Building automation: map linters/CI gates to
CC-* IDs.
- Resolving recurring review debates: align on rule IDs, scope, and exceptions.
When NOT to Use This Skill
Decision Tree: Base Rule vs Overlay vs Exception
Feedback needed: [What kind of guidance is this?]
├─ Universal, cross-language rule? → Add/modify `CC-*` in `references/clean-code-standard.md`
│
├─ Language/framework-specific nuance? → Add overlay entry referencing existing `CC-*`
│
└─ One-off constraint or temporary tradeoff?
├─ Timeboxed? → Add waiver with expiry + tracking issue
└─ Permanent? → Propose a new rule or revise scope/exception criteria
Navigation
Resources
- references/clean-code-standard.md
- references/code-quality-operational-playbook.md — Legacy operational playbook (RULE-01–RULE-13)
- references/clean-code-operational-checklist.md
- references/clean-coder-operational-checklist.md
- references/code-complete-operational-checklist.md
- references/pragmatic-programmer-operational-checklist.md
- references/practice-of-programming-operational-checklist.md
- references/working-effectively-with-legacy-code-operational-checklist.md
- references/art-of-clean-code-operational-checklist.md
- references/refactoring-operational-checklist.md
- references/design-patterns-operational-checklist.md
- data/sources.json — Durable external references for review, security-by-design, and observability
- CONVENTIONS.md — Skill structure and validation conventions
- SKILL-TEMPLATE.md — Copy-paste starter for new skills
- sources-schema.json — JSON schema for
data/sources.json
- skill-dependencies.json — Related-skills dependency graph
Templates
- assets/checklists/backend-api-review-checklist.md
- assets/checklists/secure-code-review-checklist.md
- assets/checklists/frontend-performance-a11y-checklist.md
- assets/checklists/mobile-release-checklist.md
- assets/checklists/ux-design-review-checklist.md
- assets/checklists/ux-research-plan-template.md
Utilities
- utilities/README.md
- utilities/auth-utilities.md
- utilities/error-handling.md
- utilities/config-validation.md
- utilities/resilience-utilities.md
- utilities/logging-utilities.md
- utilities/observability-utilities.md
- utilities/testing-utilities.md
- utilities/llm-utilities.md
Related Skills
Optional: AI/Automation
- Map automation findings to
CC-* IDs (linters, SAST, dependency scanning) so humans can review impact, not tooling noise.
- Keep AI-assisted suggestions advisory; human reviewers approve/deny with rule citations (https://conventionalcomments.org/).
Trend Awareness Protocol
IMPORTANT: When users ask recommendation questions about clean code standards, linters, or code quality tools, you MUST use a web search capability (if available) to check current trends before answering. If web search is unavailable, say so and answer using data/sources.json, clearly flagging that the recommendation may be stale.
Trigger Conditions
- "What's the best linter for [language]?"
- "What should I use for [code quality/static analysis]?"
- "What's the latest in clean code practices?"
- "Current best practices for [code standards/formatting]?"
- "Is [ESLint/Prettier/Biome] still relevant in 2026?"
- "[Biome] vs [ESLint] vs [other]?"
- "Best static analysis tool for [language]?"
Required Searches
- Search:
"clean code best practices 2026"
- Search:
"[specific linter] vs alternatives 2026"
- Search:
"code quality tools trends 2026"
- Search:
"[language] linter comparison 2026"
What to Report
After searching, provide:
- Current landscape: What linters/formatters are popular NOW
- Emerging trends: New tools, standards, or patterns gaining traction
- Deprecated/declining: Tools/approaches losing relevance or support
- Recommendation: Based on fresh data, not just static knowledge
Example Topics (verify with fresh search)
- JavaScript/TypeScript linters (ESLint, Biome, oxlint)
- Formatters (Prettier, dprint, Biome)
- Python quality (Ruff, mypy, pylint)
- Go linting (golangci-lint, staticcheck)
- Rust analysis (clippy, cargo-deny)
- Code quality metrics and reporting tools
- AI-assisted code review tools
1---2name: software-clean-code-standard3description: Canonical, cross-language clean code standard with stable rule IDs (CC-*). Use when writing/reviewing code, defining team standards, or mapping lint/CI findings to consistent CC-* rule citations.4---5
6# Clean Code Standard — Quick Reference
7
8This skill is the authoritative clean code standard for this repository's shared skills. It defines stable rule IDs (`CC-*`), how to apply them in reviews, and how to extend them safely via language overlays and explicit exceptions.
9
10**Modern Best Practices (January 2026)**: Prefer small, reviewable changes and durable change context (https://google.github.io/eng-practices/review/developer/small-cls.html, https://google.github.io/eng-practices/review/developer/cl-descriptions.html). Use normative language consistently (RFC 2119: https://www.rfc-editor.org/rfc/rfc2119). Treat security-by-design and secure defaults as baseline (OWASP Top 10: https://owasp.org/www-project-top-ten/, NIST SSDF SP 800-218: https://csrc.nist.gov/pubs/sp/800/218/final). Build observable systems (OpenTelemetry: https://opentelemetry.io/docs/). For current tool choices, consult `data/sources.json`.
11
12---
13
14## Quick Reference
15
16| Task | Tool/Framework | Command | When to Use |
17|------|-----|---------|-------------|
18| Cite a standard | `CC-*` rule ID | N/A | PR review comments, design discussions, postmortems |
19| Categorize feedback | `CC-NAM`, `CC-ERR`, `CC-SEC`, etc. | N/A | Keep feedback consistent without "style wars" |
20| Add stack nuance | Language overlay | N/A | When the base rule is too generic for a language/framework |
21| Allow an exception | Waiver record | N/A | When a rule must be violated with explicit risk |
22| Reuse shared checklists | `assets/checklists/` | N/A | When you need product-agnostic review/release checklists |
23| Reuse utility patterns | `utilities/` | N/A | When extracting shared auth/logging/errors/resilience/testing utilities |
24
25## When to Use This Skill
26
27- Defining or enforcing clean code rules across teams and languages.
28- Reviewing code: cite `CC-*` IDs and avoid restating standards in reviews.
29- Building automation: map linters/CI gates to `CC-*` IDs.
30- Resolving recurring review debates: align on rule IDs, scope, and exceptions.
31
32## When NOT to Use This Skill
33
34- **Deep security audits**: Use [software-security-appsec](../software-security-appsec/SKILL.md) for OWASP/SAST deep dives beyond `CC-SEC-*` baseline.
35- **Review workflow mechanics**: Use [software-code-review](../software-code-review/SKILL.md) for PR workflow, reviewer assignment, and feedback patterns.
36- **Refactoring execution**: Use [qa-refactoring](../qa-refactoring/SKILL.md) for step-by-step refactoring patterns and quality gates.
37- **Architecture decisions**: Use [software-architecture-design](../software-architecture-design/SKILL.md) for system-level tradeoffs beyond code-level rules.
38
39## Decision Tree: Base Rule vs Overlay vs Exception
40
41```text
42Feedback needed: [What kind of guidance is this?]
43 ├─ Universal, cross-language rule? → Add/modify `CC-*` in `references/clean-code-standard.md`
44 │
45 ├─ Language/framework-specific nuance? → Add overlay entry referencing existing `CC-*`
46 │
47 └─ One-off constraint or temporary tradeoff?
48 ├─ Timeboxed? → Add waiver with expiry + tracking issue
49 └─ Permanent? → Propose a new rule or revise scope/exception criteria
50```
51
52---
53
54## Navigation
55
56**Resources**
57- [references/clean-code-standard.md](references/clean-code-standard.md)
58- [references/code-quality-operational-playbook.md](references/code-quality-operational-playbook.md) — Legacy operational playbook (RULE-01–RULE-13)
59- [references/clean-code-operational-checklist.md](references/clean-code-operational-checklist.md)
60- [references/clean-coder-operational-checklist.md](references/clean-coder-operational-checklist.md)
61- [references/code-complete-operational-checklist.md](references/code-complete-operational-checklist.md)
62- [references/pragmatic-programmer-operational-checklist.md](references/pragmatic-programmer-operational-checklist.md)
63- [references/practice-of-programming-operational-checklist.md](references/practice-of-programming-operational-checklist.md)
64- [references/working-effectively-with-legacy-code-operational-checklist.md](references/working-effectively-with-legacy-code-operational-checklist.md)
65- [references/art-of-clean-code-operational-checklist.md](references/art-of-clean-code-operational-checklist.md)
66- [references/refactoring-operational-checklist.md](references/refactoring-operational-checklist.md)
67- [references/design-patterns-operational-checklist.md](references/design-patterns-operational-checklist.md)
68- [data/sources.json](data/sources.json) — Durable external references for review, security-by-design, and observability
69- [CONVENTIONS.md](CONVENTIONS.md) — Skill structure and validation conventions
70- [SKILL-TEMPLATE.md](SKILL-TEMPLATE.md) — Copy-paste starter for new skills
71- [sources-schema.json](sources-schema.json) — JSON schema for `data/sources.json`
72- [skill-dependencies.json](skill-dependencies.json) — Related-skills dependency graph
73
74**Templates**
75- [assets/checklists/backend-api-review-checklist.md](assets/checklists/backend-api-review-checklist.md)
76- [assets/checklists/secure-code-review-checklist.md](assets/checklists/secure-code-review-checklist.md)
77- [assets/checklists/frontend-performance-a11y-checklist.md](assets/checklists/frontend-performance-a11y-checklist.md)
78- [assets/checklists/mobile-release-checklist.md](assets/checklists/mobile-release-checklist.md)
79- [assets/checklists/ux-design-review-checklist.md](assets/checklists/ux-design-review-checklist.md)
80- [assets/checklists/ux-research-plan-template.md](assets/checklists/ux-research-plan-template.md)
81
82**Utilities**
83- [utilities/README.md](utilities/README.md)
84- [utilities/auth-utilities.md](utilities/auth-utilities.md)
85- [utilities/error-handling.md](utilities/error-handling.md)
86- [utilities/config-validation.md](utilities/config-validation.md)
87- [utilities/resilience-utilities.md](utilities/resilience-utilities.md)
88- [utilities/logging-utilities.md](utilities/logging-utilities.md)
89- [utilities/observability-utilities.md](utilities/observability-utilities.md)
90- [utilities/testing-utilities.md](utilities/testing-utilities.md)
91- [utilities/llm-utilities.md](utilities/llm-utilities.md)
92
93**Related Skills**
94- [../software-code-review/SKILL.md](../software-code-review/SKILL.md) — Review workflow and judgment; cite `CC-*` IDs
95- [../software-security-appsec/SKILL.md](../software-security-appsec/SKILL.md) — Security deep dives beyond baseline `CC-SEC-*`
96- [../qa-refactoring/SKILL.md](../qa-refactoring/SKILL.md) — Refactoring execution patterns and quality gates
97- [../software-architecture-design/SKILL.md](../software-architecture-design/SKILL.md) — System-level tradeoffs and boundaries
98
99---
100
101## Optional: AI/Automation
102
103- Map automation findings to `CC-*` IDs (linters, SAST, dependency scanning) so humans can review impact, not tooling noise.
104- Keep AI-assisted suggestions advisory; human reviewers approve/deny with rule citations (https://conventionalcomments.org/).
105
106---
107
108## Trend Awareness Protocol
109
110**IMPORTANT**: When users ask recommendation questions about clean code standards, linters, or code quality tools, you MUST use a web search capability (if available) to check current trends before answering. If web search is unavailable, say so and answer using `data/sources.json`, clearly flagging that the recommendation may be stale.
111
112### Trigger Conditions
113
114- "What's the best linter for [language]?"
115- "What should I use for [code quality/static analysis]?"
116- "What's the latest in clean code practices?"
117- "Current best practices for [code standards/formatting]?"
118- "Is [ESLint/Prettier/Biome] still relevant in 2026?"
119- "[Biome] vs [ESLint] vs [other]?"
120- "Best static analysis tool for [language]?"
121
122### Required Searches
123
1241. Search: `"clean code best practices 2026"`
1252. Search: `"[specific linter] vs alternatives 2026"`
1263. Search: `"code quality tools trends 2026"`
1274. Search: `"[language] linter comparison 2026"`
128
129### What to Report
130
131After searching, provide:
132
133- **Current landscape**: What linters/formatters are popular NOW
134- **Emerging trends**: New tools, standards, or patterns gaining traction
135- **Deprecated/declining**: Tools/approaches losing relevance or support
136- **Recommendation**: Based on fresh data, not just static knowledge
137
138### Example Topics (verify with fresh search)
139
140- JavaScript/TypeScript linters (ESLint, Biome, oxlint)
141- Formatters (Prettier, dprint, Biome)
142- Python quality (Ruff, mypy, pylint)
143- Go linting (golangci-lint, staticcheck)
144- Rust analysis (clippy, cargo-deny)
145- Code quality metrics and reporting tools
146- AI-assisted code review tools