- Home
- Skills
- Agents & Orchestration
- Architect Skill Router (companion)
Architect Skill Router (companion)
Routes an architecture request to the installed Architect skills that own it, and plans what to load in order.
Free
Works with the AI tools you already use
Architect Skill Router (companion)
Example session with this skill installed
Route and plan the execution sequence of Architect skills for our Enterprise Event-Driven Payment Migration.
- Objective: Decompose our legacy monolith payment processing into an asynchronous, event-driven microservices architecture with strict security and reliability controls.
- Deciders: Principal Enterprise Architect (Marcus Vance) and Core Engineering Director (Sarah Chen).
- Scope Requirements:
- Overall asynchronous messaging topology, event schemas, and transactional outbox.
- REST API contracts for public merchant checkout and idempotency guarantees.
- Zero-trust security threat model, OAuth 2.0 PKCE profile, and API key management.
- Kubernetes platform multi-tenant topology and container autoscaling.
- Reliability engineering: Service Level Objectives (SLOs), error budgets, and operational failover runbooks.
- Tension: Tech leads attempted to begin coding simultaneously without defining handoff boundaries, resulting in schema drift between payment APIs and event topics. Marcus Vance mandates a sequenced skill DAG defining artifact lineage and strict ownership before implementation starts.
Write the route plan under docs/architecture/routing/.
- Read your context and instructions
- Compiled the architect router companion
- Generated the design tokens stylesheet
Wrote docs/architecture/routing/skill-route-plan.md. Complete multi-skill route plan and dependency DAG orchestrating 8 specialized Architect skills across 4 execution phases for the Enterprise Event-Driven Payment Migration.
Architect Skill Route Plan: Enterprise Event-Driven Payment Migration [ROUTE-PAY-001]
1. Request Analysis & Intent Classification
The objective is decomposing a legacy monolithic payment processing engine into an asynchronous, event-driven microservices platform. This initiative requires coordination across four distinct technical domains: Backend APIs, Asynchronous Messaging, Cloud Infrastructure & Security, and Reliability Operations.
| Intake Requirement | Target Domain | Selected Skill ID | Rationale |
|---|---|---|---|
| Async messaging topology & schemas | Asynchronous Architecture | event-driven-architect | Owns topic topology, partition keying, and event-command boundaries. |
| Dual-write consistency & outbox | Backend Architecture | outbox-design | Specializes in transactional outbox persistence and CDC relay mechanics. |
| Merchant API endpoints & OpenAPI | Backend APIs | rest-api-design | Owns HTTP contract, cursor pagination, and RFC 9457 error models. |
| Duplicate charge protection | Backend APIs | idempotency-design | Owns idempotency keys, composite scoping, and in-flight locking. |
| Threat analysis of payment flow | Application Security | threat-modeling-task | Evaluates STRIDE threats, entry surfaces, and mitigation controls. |
| Delegated merchant authorization | Security & Identity | oauth-design | Defines OAuth 2.0 Authorization Code + S256 PKCE profile. |
| Shared Kubernetes infrastructure | DevOps & Cloud | kubernetes-architect | Designs multi-tenant clusters, tainted node pools, and network isolation. |
| Checkout availability & runbooks | SRE & Operations | sli-slo-design | Owns CUJ indicators, error budget mathematics, and burn-rate alerting. |
2. Selected Skills and Execution DAG
The migration plan is structured into four sequential phases forming a strict Directed Acyclic Graph (DAG). Foundation contracts precede transport specifications, which precede infrastructure and reliability operational baselines.
Phase 1: Security & API Contract Foundations
├── [threat-modeling-task] ──► Threat Model & Abuse Scenarios
│ │
└── [rest-api-design] ───────────────┼────────────────────────┐
▼ ▼
Phase 2: Authorization & Resilience Mechanics
├── [oauth-design] ◄─── (Needs API scopes) │
├── [idempotency-design] ◄─── (Needs POST refund contracts) │
└── [event-driven-architect] ◄─── (Needs payment domain events)
│
▼
Phase 3: Event Relaying & Platform Provisioning
├── [outbox-design] ◄─── (Needs topic schemas & Kafka cluster)
└── [kubernetes-architect] ◄─── (Needs workload resource specs)
│
▼
Phase 4: Reliability Governance & Operations
└── [sli-slo-design] ◄─── (Needs end-to-end user checkout journey)
3. Boundary & Responsibility Matrix
| Skill ID | Primary Deliverable | Owned Scope | Forbidden Scope Overlap |
|---|---|---|---|
threat-modeling-task | threat-model-report.md | STRIDE analysis, trust boundaries, attacker profiles | Does not design token crypto or write runbooks |
rest-api-design | rest-api-contract.md | HTTP methods, status codes, OpenAPI schema | Does not configure database outbox tables |
oauth-design | oauth-profile-spec.md | Authorization code flow, PKCE S256, token rotation | Does not evaluate business fraud scores |
idempotency-design | idempotency-contract.md | Composite key tuple, DynamoDB lock, payload hash | Does not configure Kafka topics |
event-driven-architect | eda-architecture.md | Kafka topic topology, CloudEvents schemas, partitions | Does not implement DB replication slots |
outbox-design | outbox-pattern-contract.md | PostgreSQL outbox table, Debezium CDC, DLQ | Does not define merchant REST endpoints |
kubernetes-architect | kubernetes-architect-overview.md | EKS node pools, Cilium NetworkPolicy, PSS restricted | Does not write application business code |
sli-slo-design | sli-slo-contract.md | Availability/latency SLIs, error budget burn rates | Does not configure IAM policies |
4. Intake Context and Artifact Lineage
[threat-modeling-task] ──► docs/architecture/security/threat-model.md
│
▼
[oauth-design] ──────────► docs/architecture/security/oauth-profile.md
│
[rest-api-design] ───────► docs/architecture/api/rest-contract.md
│
▼
[idempotency-design] ────► docs/architecture/api/idempotency-contract.md
│
[event-driven-architect] ─► docs/architecture/eda/eda-architecture.md
│
▼
[outbox-design] ─────────► docs/architecture/eda/outbox-contract.md
│
[kubernetes-architect] ──► docs/architecture/k8s/platform-overview.md
│
▼
[sli-slo-design] ────────► docs/architecture/sre/sli-slo-contract.md
5. Verification & Route Self-Check
No validator was supplied, so no command was run.
Reviewer self-check against routing invariants:
Catalog Verification: PASS. All 8 skill IDs (threat-modeling-task, rest-api-design, oauth-design, idempotency-design, event-driven-architect, outbox-design, kubernetes-architect, sli-slo-design) exist in references/catalog.yml.
- DAG Integrity: PASS. Zero cyclical loops detected; dependencies cascade deterministically across 4 phases.
- Single Ownership: PASS. Every architectural asset has exactly one designated primary skill owner.
- Completeness: PASS. Addresses all five intake concerns stated by Marcus Vance and Sarah Chen.
Next steps
- Present this Route Plan to Marcus Vance and Sarah Chen for Architecture Review Board endorsement.
- Initialize Phase 1 execution by loading
threat-modeling-taskandrest-api-design. - Feed resulting threat model boundaries and REST contracts into Phase 2 execution lanes (
oauth-design,idempotency-design, andevent-driven-architect).
architect-skill-router-companion-tokens.css
CSS · design tokens
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
What it does
This skill is the metadata-only entry point for unclassified architecture requests. It resolves the requested decision and deliverable, accountable authority, artifact ownership, required dependencies, and evidence obligations; selects the smallest compatible leaves; and emits a progressive load and handoff plan. It does not perform architecture, author artifacts, execute tasks, spawn agents, or infer a route from names.
Use it when
- The request is architectural but exact authoritative leaf IDs are not supplied
- Multiple plausible owners overlap and the requested decision/deliverable must discriminate them
- A domain authority and a narrow task procedure must be paired without transferring ownership
- Prerequisite producer/consumer contracts and execution order must be identified before loading bodies
- Ambiguity, missing authority, incompatible ownership, unavailable packages, or stale metadata must block deterministically
- Context cost requires bounded metadata discovery and smallest-leaf progressive loading
What you get
The output is one structured routing decision with a stable status, reason, bounded candidates, and the smallest compatible selected leaf set — a domain leaf, a task leaf, or a domain-plus-task pair — each carrying its SKILL.md and references/output-contract.md authority files (two files for one leaf, four for a pair). This meta-skill produces no architecture artifact.
What it will not do
Do not use when authoritative leaf IDs are already resolved, or merely to perform architecture, write a design/specification/diagram/ADR, plan a generic task, search a catalog, spawn agents, execute a workflow, choose tools, or route from titles/keywords.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- references/catalog.yml
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
1 install
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 12 days ago
- Free to download with an account