Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Anti Patterns

ASecurity

Catalogue of known SDLC anti-patterns that great_cto agents must actively reject when reviewing architecture, plans, code, or post-mortems. Used by architect (pre-impl), pm (planning), senior-dev (impl), l3-support (post-incident).

36 stars
0 votes
0 copies
0 views
Added 9/22/2026
code-qualitygorailskubernetestestingdebugginggitapidatabase

Works with

api

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add NVlabs/Skill2Env --skill anti-patterns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Anti Patterns?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Anti Patterns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nvlabs-anti-patterns/badge)](https://www.skillsdirectory.com/skills/nvlabs-anti-patterns)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: anti-patterns
description: Catalogue of known SDLC anti-patterns that great_cto agents must actively reject when reviewing architecture, plans, code, or post-mortems. Used by architect (pre-impl), pm (planning), senior-dev (impl), l3-support (post-incident).
when_to_use: |
  Apply when:
  - architect is writing ARCH/ADR and might be tempted by a known bad pattern
  - pm is decomposing tasks and the breakdown smells like a known failure mode
  - senior-dev is implementing and considers a "quick fix" that is anti-pattern
  - l3-support is doing root-cause and finds an anti-pattern as the cause
  - any agent reviewing third-party code that exhibits anti-patterns
effort: low
allowed-tools: Read, Grep, Glob
paths:
  - "docs/**"
  - "src/**"
  - "lib/**"
---

# SDLC anti-patterns to reject

Reference catalogue. Cite the anti-pattern by name when blocking a
proposal — gives the user a clear vocabulary to discuss the issue.

## Architecture anti-patterns

### A-1. God service
**Smell:** One service does auth, billing, search, file storage, and email.
**Why bad:** Single deploy unit, single point of failure, every team
touches it, change velocity drops over time.
**Fix:** Split by business capability (DDD bounded context).

### A-2. Distributed monolith
**Smell:** 12 microservices but they share a database and deploy together.
**Why bad:** All cost of distributed (latency, eventual consistency, ops
overhead) with none of the benefits (independent deploy, isolation).
**Fix:** Either truly separate (own DB, own deploy pipeline) or merge.

### A-3. Synchronous chains
**Smell:** Request → Service A → Service B → Service C → Service D.
**Why bad:** Compound failure probability, p99 latency adds up.
**Fix:** Async with events, or co-locate hot path.

### A-4. Premature optimization
**Smell:** Custom Redis Lua scripts, hand-tuned binary protocols, before
the first paying user.
**Why bad:** Complexity cost paid up front, never recouped.
**Fix:** Start simple. Optimize when you have load data.

### A-5. Resume-driven development
**Smell:** "Let's use Kubernetes / GraphQL / event sourcing / DDD" with
no current pain it solves.
**Why bad:** Optimizes for engineer's resume, not user's outcome.
**Fix:** Ask "what's the simplest thing that could work?"

## Plan / process anti-patterns

### P-1. Big-bang rewrite
**Smell:** "Let's rewrite this in <new framework>."
**Why bad:** 80% of rewrites fail. The old system has years of bug fixes
baked in.
**Fix:** Strangler-fig. New behaviour in new code, old code coexists,
delete when traffic moves.

### P-2. Hero culture
**Smell:** "Senior X always fixes the 3am incidents."
**Why bad:** Bus factor 1. X burns out. Knowledge doesn't transfer.
**Fix:** Runbooks, post-mortems, rotating on-call, pair-debugging.

### P-3. No reversibility plan
**Smell:** Plan ships a one-way door (data migration, public API change,
breaking-contract release).
**Why bad:** If wrong, recovery is days or weeks.
**Fix:** Mandate dry-run + rollback path before approval.

### P-4. Plan without timeboxes
**Smell:** Tasks named "implement feature X" with no end criteria.
**Why bad:** Open scope, time inflates to fit.
**Fix:** Each task ≤ 4 hours, with explicit "done = X" criteria.

## Code-level anti-patterns

### C-1. God class / God function
**Smell:** A class > 500 lines or function > 100 lines doing 5 unrelated things.
**Why bad:** Tests become integration tests. Diff readability collapses.
**Fix:** Single responsibility. Extract collaborators.

### C-2. Stringly typed
**Smell:** Status passed as strings ("open", "closed", "blocked") with no enum.
**Why bad:** Typos compile. New status forgotten in switch.
**Fix:** Enum / discriminated union / branded type.

### C-3. Catch-and-continue
**Smell:**
```js
try { doThing(); } catch (e) { console.log(e); }
```
**Why bad:** Hides bugs. Silent corruption.
**Fix:** Catch only what you can handle; re-throw the rest; log with context.

### C-4. Hardcoded secrets
**Smell:** API keys, passwords, DB URLs in source.
**Why bad:** Leaks in git history forever; rotation requires force-push (impossible).
**Fix:** Env vars or secret manager. Pre-commit hook to grep for `sk-`, `ghp_`, etc.

## Incident / ops anti-patterns

### O-1. No SLO
**Smell:** "Production seems slow today" but no SLO target.
**Why bad:** Can't tell breach from normal.
**Fix:** Set p99 latency, error rate, availability SLOs. Track burn.

### O-2. Alert spam
**Smell:** Every error pages. Engineers stop reading alerts.
**Why bad:** Real incidents get missed in noise.
**Fix:** Page only on user-visible failure. Other signals to dashboard, not pager.

### O-3. Post-mortem blame
**Smell:** "Engineer X deployed without testing."
**Why bad:** Suppresses future post-mortems. Blame doesn't fix the system.
**Fix:** Blameless post-mortems. Focus on missing guardrails, not the human.

### O-4. Snowflake servers
**Smell:** "Don't reboot SRV-PROD-3, it has special config that's not in IaC."
**Why bad:** Disaster recovery impossible.
**Fix:** Everything in IaC. Servers are cattle, not pets.

## How to use this catalogue

When you find one of these in a proposal/review:

1. Cite the code (A-3, P-1, etc.) so the user has a vocabulary
2. Quote the specific smell from the proposal
3. Propose the specific fix
4. If the user disagrees, capture as ADR with the alternatives section
   filled in

## When NOT to apply

- Hobby projects, learning exercises — anti-patterns are about scale
- Throwaway code with explicit `// TODO delete in 2 weeks`
- Time-boxed POCs where the goal is "does the API actually work"

Attribution

NVlabsNVlabs
View sourceMore from NVlabs →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Caveman Review

Ultra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", "/review", or invokes /caveman-review. Auto-triggers when reviewing pull requests.

1066601 votes

Caveman Commit

Ultra-compressed commit message generator. Cuts noise from commit messages while preserving intent and reasoning. Conventional Commits format. Subject ≤50 chars, body only when "why" isn't obvious. Use when user says "write a commit", "commit message", "generate commit", "/commit", or invokes /caveman-commit. Auto-triggers when staging changes.

1066601 votes

Springboot Verification

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

2456590 votes

Verification Loop

一个全面的 Claude Code 会话验证系统。

2456590 votes

Django Verification

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

2456590 votes
View all in code-quality →