Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Defense In Depth

ASecurity

Multi-layer validation to catch bugs before they escape

14 stars
0 votes
0 copies
0 views
Added 2/7/2026
testinggoapi

Works with

api

Security Analysis

A100/100

Scanned 2/12/2026

$npx -y skills add a-ariff/ariff-claude-plugins --skill defense-in-depth --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Defense In Depth?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Defense In Depth
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/a-ariff-defense-in-depth/badge)](https://www.skillsdirectory.com/skills/a-ariff-defense-in-depth)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: defense-in-depth
description: Multi-layer validation to catch bugs before they escape
version: 1.0.0
author: Ariff
when_to_use: When making changes - validate at multiple layers
---

# Defense in Depth

## Philosophy

```
MULTIPLE INDEPENDENT VALIDATION LAYERS
Each layer catches what others miss
```

One check can fail silently. Four layers rarely do.

## The Four Layers

### Layer 1: Type/Syntax
```
What: Static analysis, types, linting
Catches: Typos, syntax errors, type mismatches
Run: First, before anything else
```

### Layer 2: Unit Tests
```
What: Individual function/module tests
Catches: Logic errors, edge cases, regressions
Run: After each code change
```

### Layer 3: Integration Tests
```
What: Component interaction tests
Catches: Interface mismatches, data flow errors
Run: After unit tests pass
```

### Layer 4: End-to-End
```
What: Full system tests, user scenarios
Catches: Missing requirements, workflow bugs
Run: Before claiming complete
```

## The Pipeline

```
Code Change
    ↓
[Layer 1: Lint/Type Check]
    ↓ PASS?
[Layer 2: Unit Tests]
    ↓ PASS?
[Layer 3: Integration Tests]
    ↓ PASS?
[Layer 4: E2E / Manual Check]
    ↓ PASS?
Done
```

**Fail at any layer → FIX before proceeding**

## Why Every Layer Matters

| Without This Layer | What Escapes |
|-------------------|--------------|
| No type checks | Undefined calls crash at runtime |
| No unit tests | Logic bugs slip through |
| No integration | Components don't work together |
| No E2E | User workflows broken |

## Implementation Patterns

### For Code Changes
```
1. Make change
2. Run linter immediately
3. Run affected unit tests
4. Run integration suite
5. Test the actual feature
```

### For Bug Fixes
```
1. Write failing test first
2. Fix the bug
3. Run all tests (regression check)
4. Verify original symptom gone
```

### For New Features
```
1. Write unit tests for new logic
2. Implement feature
3. Add integration tests
4. Verify against requirements
```

## Layer-Specific Commands

Configure per project:

```yaml
layer_1:
  command: "npm run lint && npm run typecheck"
  when: "On save, before commit"
  
layer_2:
  command: "npm run test:unit"
  when: "After code changes"
  
layer_3:
  command: "npm run test:integration"
  when: "After unit tests pass"
  
layer_4:
  command: "npm run test:e2e"
  when: "Before claiming done"
```

## Recovery Procedures

### Layer 1 Fails
```
→ Syntax/type error in your code
→ Fix immediately, don't proceed
→ Never commit with lint errors
```

### Layer 2 Fails
```
→ Logic error or regression
→ Check: Did you break something?
→ Check: Is your new test wrong?
→ Fix root cause, not symptoms
```

### Layer 3 Fails
```
→ Interface/contract broken
→ Check: API changes?
→ Check: State management issues?
→ May need to update multiple files
```

### Layer 4 Fails
```
→ User-visible problem
→ Trace back through layers
→ Ask: Which layer SHOULD have caught this?
→ Add test to that layer
```

## Integration with Checker Agents

- `pre-action-verifier` → Runs before each layer
- `assumption-checker` → Validates test assumptions
- `scope-boundary-checker` → Ensures tests cover scope
- `rollback-planner` → Ready if pipeline fails

Attribution

a-ariffa-ariff
View sourceSee grades on GitHubMore from a-ariff →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Screen Reader Testing

Practical guide to testing web applications with screen readers for comprehensive accessibility validation.

401991 votes

Tdd Workflow

在编写新功能、修复错误或重构代码时使用此技能。强制执行测试驱动开发,包含单元测试、集成测试和端到端测试,覆盖率超过80%。

2456590 votes

Eval Harness

克劳德代码会话的正式评估框架,实施评估驱动开发(EDD)原则

2456590 votes

Python Testing

使用pytest、TDD方法、夹具、模拟、参数化和覆盖率要求的Python测试策略。

2456590 votes

Django Tdd

Django测试策略,包括pytest-django、TDD方法论、factory_boy、模拟、覆盖率以及测试Django REST Framework API。

2456590 votes
View all in testing →