{"schema_version":2,"skill":"go-service-boundaries","cases":[{"id":"route-stream-timeout","kind":"routing","split":"development","prompt":"Review a Go gRPC stream and HTTP endpoint for message limits, cancellation, status mapping, and shutdown.","should_activate":true,"reason":"Network protocol boundaries dominate."},{"id":"avoid-retry-storm","kind":"routing","split":"development","prompt":"Three service layers retry and overload the leaf dependency.","should_activate":false,"reason":"System retry amplification belongs to go-service-resilience.","confuses_with":["go-service-resilience"]},{"id":"quality-http-body","kind":"quality","split":"development","prompt":"Fix the fixture so HTTP input is bounded before allocation, request context is honored, and the body is closed.","fixture":"evaluations/fixtures/http-lifecycle","expected_invariants":["Bounds bytes before decoding","Propagates request context"],"forbidden_outcomes":["Sets every server timeout to one arbitrary value"],"graders":[{"id":"boundary-terms","kind":"go-test","target":"./...","weight":1}]},{"id":"quality-grpc-status","kind":"quality","split":"development","prompt":"Map domain validation, conflict, overload, and cancellation into a gRPC adapter.","expected_invariants":["Preserves distinct canonical statuses","Does not leak internal error details"],"forbidden_outcomes":["Maps all failures to Unknown"],"graders":[{"id":"status-semantics","kind":"contains","required":["status","cancellation"],"weight":1}]},{"id":"quality-mtls-generation-cutover","kind":"quality","split":"development","prompt":"Review a Go gateway change that rotates an upstream mTLS certificate, trust roots, proxy, and route policy while requests and long-lived response bodies are active. The change atomically swaps only the policy pointer, mutates the shared http.Transport fields in place, and never retires old pools. New requests must use one policy and connection generation; admitted requests may finish on the generation they captured. Report the required cutover and ownership invariants without implementing it.","expected_invariants":["Builds and validates a private replacement transport and TLS configuration instead of mutating an in-use shared transport","Publishes route policy and its client or transport as one immutable generation captured once per admitted request","Prevents new admissions to the retired generation while allowing already admitted operations to finish with it","Closes obsolete idle connections and separately accounts for active response bodies or long-lived streams before final release","Bounds retained generations and makes rotation failure leave the last known-good generation available"],"forbidden_outcomes":["Claims concurrent-safe Transport permits field mutation during use","Claims an atomic policy pointer also atomically changes separate transport fields","Treats CloseIdleConnections as termination of active response bodies or streams"],"graders":[{"id":"transport-generation-review","kind":"contains","required":["generation","idle"],"weight":1}]},{"id":"quality-http-json-message-boundary-review","kind":"quality","split":"development","prompt":"Review a Go funds-transfer HTTP handler. It accepts any Content-Type and Content-Encoding, calls json.Decoder.Decode once into a struct containing Amount any, invokes the domain service whenever that call returns nil, and only then wraps the remaining body with MaxBytesReader. Unknown fields are silently ignored. Two upstream components disagree about which duplicate JSON member wins. Decode errors are logged with the raw body, and the same partially populated request object is reused from a pool. State the wire, resource, decoding, validation, ownership, and error-mapping invariants without choosing a web framework.","expected_invariants":["Applies a hard request-body limit before JSON decoding","Rejects unsupported media types and content encodings before parsing","Bounds decompressed bytes when compressed bodies are supported","Decodes exact identifiers and money into validated typed fields rather than float64 through any","Requires one complete JSON value followed only by whitespace and EOF","Chooses unknown-field tolerance explicitly for each versioned API contract","Rejects duplicate identity amount routing or operation fields before ordinary semantic use","Discards the entire private candidate DTO after any decode error","Validates and authorizes the complete candidate before constructing or invoking one domain command","Returns stable non-sensitive categories for oversized malformed unsupported validation conflict and internal failures","Keeps raw bodies credentials and parser internals out of logs and responses","Stops decode and downstream work when the request context is canceled"],"forbidden_outcomes":["Claims one successful Decoder.Decode proves the body contains only one JSON value","Claims DisallowUnknownFields rejects duplicate JSON names","Uses fields from a partially decoded request after an error","Places the byte limit after decoding or allocation"],"graders":[{"id":"http-json-message-boundary-review","kind":"contains","required":["duplicate","EOF"],"weight":1}]}]}
